Luke, We're taking a different approach towards XSS detection, take a look at [0] and specially the context stuff
[0] http://sourceforge.net/apps/trac/w3af/browser/branches/xss/plugins/audit/xss.py Regards, On Mon, Sep 17, 2012 at 12:18 AM, luke <lukesun...@gmail.com> wrote: > Does w3af support to check new html5 tag like <video> <audio> autofocus > etc. that cause XSS attack ? > > > On Thu, Sep 13, 2012 at 8:15 AM, Andres Riancho <andres.rian...@gmail.com> > wrote: >> >> Luke, >> >> I would test it against sites that have CORS headers enabled, some of >> them: >> >> sourceforge.net >> nbcolympics.com >> gazeta.ru >> mamba.ru >> investopedia.com >> >> And also some negative tests would be nice (test against sites >> that don't have that enabled). Finally, also please spend some time >> reading the source code if possible. >> >> Regards, >> >> On Wed, Sep 12, 2012 at 8:51 PM, luke <lukesun...@gmail.com> wrote: >> > Hi guys >> > >> > I am testing the w3af modules which design for check html5 vulnerablity >> > ? >> > but I can not find a good test site ? >> > does anyone know this kind of website for test ? >> > >> > -- >> > FIT1-213 >> > Department of Computer Science >> > Tsinghua University, Beijing, 100084 >> > http://about.me/anakin/bio >> > >> > >> > ------------------------------------------------------------------------------ >> > Live Security Virtual Conference >> > Exclusive live event will cover all the ways today's security and >> > threat landscape has changed and how IT managers can respond. >> > Discussions >> > will include endpoint security, mobile security and the latest in >> > malware >> > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ >> > _______________________________________________ >> > W3af-users mailing list >> > W3af-users@lists.sourceforge.net >> > https://lists.sourceforge.net/lists/listinfo/w3af-users >> > >> >> >> >> -- >> Andrés Riancho >> Project Leader at w3af - http://w3af.org/ >> Web Application Attack and Audit Framework >> Twitter: @w3af >> GPG: 0x93C344F3 > > > > > -- > FIT1-213 > Department of Computer Science > Tsinghua University, Beijing, 100084 > http://about.me/anakin/bio -- Andrés Riancho Project Leader at w3af - http://w3af.org/ Web Application Attack and Audit Framework Twitter: @w3af GPG: 0x93C344F3 ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ _______________________________________________ W3af-users mailing list W3af-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/w3af-users