As an open source penetration testing tool, IPTC-Attacker allows to create an image with IPTC metadata containing testing vectors for Cross-Site Scripting attacks. Each checkbox can be used to include a huge collection of payloads into the selected tags (HTML5sec, XSS Cheat Sheet). If a checkbox will be not selected, the string aaa'bbb"ccc<ddd is automatically included into the unchecked IPTC tag.

Therefore, testing for XSS vulnerabilities via IPTC metadata is possible by looking into the source code of the attacked Web application; strictly speaking for aaa'bbb"ccc<ddd or alternatively by verifying if, for example, alert-windows appear due to the XSS vector collection.

Features

  • Generate JPG images with IPTC metadata
  • Huge collection of XSS vectors
  • Easy to use: Generate the image, upload it to your image provider, and verify if the input if filtered

Project Samples

Project Activity

See All Activity >

Follow IPTC-Attacker

IPTC-Attacker Web Site

Other Useful Business Software
$300 Free Credits for Your Google Cloud Projects Icon
$300 Free Credits for Your Google Cloud Projects

Start building on Google Cloud with $300 in free credits. No commitment, no credit card required until you're ready to scale.

Launch your next project with $300 in free Google Cloud credits—no strings attached. Test, build, and deploy without risk. Use your credits across the entire Google Cloud platform to find what works best for your needs. After your credits are used, continue with always-free tier services. Only pay when you're ready to scale. Sign up in minutes and start exploring.
Start Free Trial
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of IPTC-Attacker!

Additional Project Details

Intended Audience

Auditors, Security Professionals, Testers

Programming Language

JavaScript, PHP

Related Categories

PHP Security Software, PHP Penetration Testing Tool, JavaScript Security Software, JavaScript Penetration Testing Tool

Registered

2014-06-30