Skip to main content

acidrain-security-script-hub

Web-oriented XSS analysis resources, JavaScript utilities, and PHP examples for authorized security testing and hands-on learning

Zur Installation springen

Quellinformationen

Repository
reason-machines/security-skills
Letzte Quellaktivität
4. August 2026 um 10:22
Erkannte Sprache von SKILL.md
Englisch
Sterne
12
Forks
1

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
acidrain-security-script-hub
description
Web-oriented XSS analysis resources, JavaScript utilities, and PHP examples for authorized security testing and hands-on learning
triggers
["how do I use acidrain for xss testing","set up acidrain security scripts","show me acidrain xss examples","test cross-site scripting with acidrain","acidrain javascript injection samples","configure acidrain php security tests","run acidrain web security analysis","acidrain authorized penetration testing"]
# AcidRain Security Script Hub Skill > Skill by [ara.so](https://ara.so) — Security Skills collection. ## What AcidRain Does AcidRain is a web security toolbox containing XSS injection resources, JavaScript utilities, and PHP examples for authorized security testing, education, and research. It provides browser-side and server-side material organized for experimentation in controlled environments. **Key capabilities:** - XSS analysis and cross-site scripting testing resources - Client-side JavaScript security utilities - Server-side PHP research examples - Injection testing samples for input/output validation - Web security helper scripts for targeted investigation **⚠️ CRITICAL:** Use only against systems you own or have explicit written authorization to test. Unauthorized use is illegal. ## Installation Clone the repository and navigate to the working directory: ```bash git clone https://github.com/henry-lewiskpp1107/acidrain-security-script-hub.git cd acidrain-security-script-hub ``` Inspect the directory structure before running any scripts: ```bash ls -la tree scripts/ # if available ``` Expected structure: ``` acidrain-security-script-hub/ ├── scripts/ │ ├── javascript/ │ ├── php/ │ └── xss/ ├── configs/ ├── examples/ ├── docs/ ├── LICENSE └── README.md ``` ## JavaScript Utilities ### Basic XSS Payload Testing Create a test environment HTML file: ```html <!DOCTYPE html> <html> <head> <title>XSS Test Environment</title> </head> <body> <h1>Authorized Testing Zone</h1> <div id="output"></div> <script> // Safe parameter extraction for testing function getTestParameter(name) { const urlParams = new URLSearchParams(window.location.search); return urlParams.get(name); } // Demonstrate unsafe output (for testing only) function displayUnsafeOutput(input) { document.getElementById('output').innerHTML = input; } // Test XSS vulnerability const userInput = getTestParameter('test'); if (userInput) { displayUnsafeOutput(userInput); } </script> </body> </html> ``` ### XSS Detection Script ```javascript // scripts/javascript/xss-detector.js class XSSDetector { constructor() { this.payloads = [ '<script>alert(1)</script>', '<img src=x onerror=alert(1)>', '<svg onload=alert(1)>', 'javascript:alert(1)', '<iframe src="javascript:alert(1)">', '<body onload=alert(1)>', '<input autofocus onfocus=alert(1)>', '"><script>alert(1)</script>' ]; } testEndpoint(url, params) { console.log(`Testing: ${url}`); this.payloads.forEach((payload, index) => { const testParams = { ...params, test: payload }; const queryString = new URLSearchParams(testParams).toString(); const testUrl = `${url}?${queryString}`; console.log(`[${index + 1}] Payload: ${payload}`); console.log(` URL: ${testUrl}`); }); } sanitizeInput(input) { const element = document.createElement('div'); element.textContent = input; return element.innerHTML; } validateOutput(html) { const dangerous = /<script|javascript:|onerror=|onload=/i; return !dangerous.test(html); } } // Usage const detector = new XSSDetector(); detector.testEndpoint('http://localhost:8000/test.php', { user: 'testuser' }); // Sanitization example const userInput = '<script>alert("xss")</script>'; const safe = detector.sanitizeInput(userInput); console.log('Sanitized:', safe); ``` ### DOM-Based XSS Analysis ```javascript // scripts/javascript/dom-xss-analyzer.js function analyzeDOMSinks() { const dangerousSinks = { 'innerHTML': document.querySelectorAll('[id]'), 'eval': 'eval() calls', 'setTimeout': 'setTimeout with string', 'setInterval': 'setInterval with string', 'document.write': 'document.write() calls', 'location': 'location manipulation' }; console.log('=== DOM XSS Sink Analysis ==='); // Check for innerHTML usage document.querySelectorAll('*').forEach(el => { const id = el.id; if (id) { console.log(`Found element with ID: ${id}`); console.log(` - Can be targeted via innerHTML`); } }); // Monitor location-based sources const sources = { 'location.href': window.location.href, 'location.search': window.location.search, 'location.hash': window.location.hash, 'document.referrer': document.referrer }; console.log('\n=== User-Controlled Sources ==='); Object.entries(sources).forEach(([name, value]) => { if (value) { console.log(`${name}: ${value}`); } }); } // Execute analysis analyzeDOMSinks(); ``` ## PHP Security Testing ### Input Validation Testing ```php <?php // scripts/php/input-validator.php class InputValidator { public static function testInputs() { $testCases = [ '<script>alert(1)</script>', '"><img src=x onerror=alert(1)>', "'; DROP TABLE users; --", '../../../etc/passwd', '${7*7}', '{{7*7}}' ]; echo "=== Input Validation Tests ===\n\n"; foreach ($testCases as $input) { echo "Testing: " . $input . "\n"; echo "Sanitized: " . self::sanitize($input) . "\n"; echo "Escaped: " . self::escape($input) . "\n\n"; } } public static function sanitize($input) { return htmlspecialchars($input, ENT_QUOTES, 'UTF-8'); } public static function escape($input) { return addslashes($input); } public static function validateEmail($email) { return filter_var($email, FILTER_VALIDATE_EMAIL); } public static function validateURL($url) { return filter_var($url, FILTER_VALIDATE_URL); } } // Run tests InputValidator::testInputs(); ?> ``` ### XSS Vulnerable Endpoint (Testing Only) ```php <?php // scripts/php/vulnerable-endpoint.php // WARNING: This is intentionally vulnerable for testing header('X-Frame-Options: DENY'); header('X-Content-Type-Options: nosniff'); $test_mode = getenv('ACIDRAIN_TEST_MODE'); if ($test_mode !== 'enabled') { die('Test mode must be explicitly enabled via ACIDRAIN_TEST_MODE=enabled'); } // Intentionally vulnerable for testing function displayUnsafe($input) { return "<div>User input: " . $input . "</div>"; } // Safe version for comparison function displaySafe($input) { return "<div>User input: " . htmlspecialchars($input, ENT_QUOTES, 'UTF-8') . "</div>"; } if (isset($_GET['unsafe'])) { echo displayUnsafe($_GET['unsafe']); } if (isset($_GET['safe'])) { echo displaySafe($_GET['safe']); } ?> ``` ### Secure Form Handler ```php <?php // scripts/php/secure-form-handler.php class SecureFormHandler { private $allowedFields = ['name', 'email', 'message']; private $errors = []; public function processForm($data) { $sanitized = []; foreach ($this->allowedFields as $field) { if (!isset($data[$field])) { $this->errors[] = "Missing field: $field"; continue; } $value = $data[$field]; // Sanitize $value = trim($value); $value = stripslashes($value); $value = htmlspecialchars($value, ENT_QUOTES, 'UTF-8'); // Validate if ($field === 'email' && !filter_var($value, FILTER_VALIDATE_EMAIL)) { $this->errors[] = "Invalid email format"; continue; } $sanitized[$field] = $value; } if (empty($this->errors)) { return ['success' => true, 'data' => $sanitized]; } return ['success' => false, 'errors' => $this->errors]; } public function getErrors() { return $this->errors; } } // Usage $handler = new SecureFormHandler(); $result = $handler->processForm($_POST); if ($result['success']) { // Process safe data $data = $result['data']; echo "Form processed successfully\n"; } else { echo "Errors:\n"; foreach ($result['errors'] as $error) { echo "- $error\n"; } } ?> ``` ## Configuration ### Environment Setup Create a `.env` file in the project root: ```bash # .env ACIDRAIN_TEST_MODE=enabled ACIDRAIN_TARGET_URL=http://localhost:8000 ACIDRAIN_LOG_LEVEL=debug ACIDRAIN_REPORT_DIR=./reports ``` Load environment variables in PHP: ```php <?php // Load configuration $dotenv = parse_ini_file('.env'); foreach ($dotenv as $key => $value) { putenv("$key=$value"); } $testMode = getenv('ACIDRAIN_TEST_MODE'); $targetUrl = getenv('ACIDRAIN_TARGET_URL'); ?> ``` ### Test Server Setup Start a PHP development server for testing: ```bash # Navigate to scripts directory cd scripts/php # Start server php -S localhost:8000 # Test endpoint curl "http://localhost:8000/vulnerable-endpoint.php?safe=<script>test</script>" ``` ## Common Testing Patterns ### XSS Reflection Testing ```javascript // Test for reflected XSS function testReflectedXSS(baseUrl, params) { const payloads = [ '<script>alert(document.domain)</script>', '<img src=x onerror=alert(1)>', '"><svg/onload=alert(1)>', 'javascript:alert(1)' ]; payloads.forEach(payload => { const testParams = { ...params, input: payload }; const url = `${baseUrl}?${new URLSearchParams(testParams)}`; console.log(`Testing URL: ${url}`); // In practice, use fetch or automated browser fetch(url) .then(response => response.text()) .then(html => { if (html.includes(payload)) { console.warn('⚠️ Potential XSS: Payload reflected'); } else { console.log('✓ Payload sanitized or filtered'); } }); }); } // Usage testReflectedXSS('http://localhost:8000/test.php', { user: 'test' }); ``` ### Stored XSS Testing
Auf GitHub ansehen
Diese SKILL.md ist sehr gross, daher zeigt SkillsMP hier nur den ersten Abschnitt. Auf GitHub ansehen