Skip to main content

acidrain-security-script-hub

Web-oriented XSS analysis resources, JavaScript utilities, and PHP examples for authorized security testing and hands-on learning

설치로 이동

소스 정보

저장소
reason-machines/security-skills
최근 소스 활동
2026년 8월 4일 10:22
감지된 SKILL.md 언어
영어
스타
12
포크
1

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
acidrain-security-script-hub
description
Web-oriented XSS analysis resources, JavaScript utilities, and PHP examples for authorized security testing and hands-on learning
triggers
["how do I use acidrain for xss testing","set up acidrain security scripts","show me acidrain xss examples","test cross-site scripting with acidrain","acidrain javascript injection samples","configure acidrain php security tests","run acidrain web security analysis","acidrain authorized penetration testing"]
# AcidRain Security Script Hub Skill > Skill by [ara.so](https://ara.so) — Security Skills collection. ## What AcidRain Does AcidRain is a web security toolbox containing XSS injection resources, JavaScript utilities, and PHP examples for authorized security testing, education, and research. It provides browser-side and server-side material organized for experimentation in controlled environments. **Key capabilities:** - XSS analysis and cross-site scripting testing resources - Client-side JavaScript security utilities - Server-side PHP research examples - Injection testing samples for input/output validation - Web security helper scripts for targeted investigation **⚠️ CRITICAL:** Use only against systems you own or have explicit written authorization to test. Unauthorized use is illegal. ## Installation Clone the repository and navigate to the working directory: ```bash git clone https://github.com/henry-lewiskpp1107/acidrain-security-script-hub.git cd acidrain-security-script-hub ``` Inspect the directory structure before running any scripts: ```bash ls -la tree scripts/ # if available ``` Expected structure: ``` acidrain-security-script-hub/ ├── scripts/ │ ├── javascript/ │ ├── php/ │ └── xss/ ├── configs/ ├── examples/ ├── docs/ ├── LICENSE └── README.md ``` ## JavaScript Utilities ### Basic XSS Payload Testing Create a test environment HTML file: ```html <!DOCTYPE html> <html> <head> <title>XSS Test Environment</title> </head> <body> <h1>Authorized Testing Zone</h1> <div id="output"></div> <script> // Safe parameter extraction for testing function getTestParameter(name) { const urlParams = new URLSearchParams(window.location.search); return urlParams.get(name); } // Demonstrate unsafe output (for testing only) function displayUnsafeOutput(input) { document.getElementById('output').innerHTML = input; } // Test XSS vulnerability const userInput = getTestParameter('test'); if (userInput) { displayUnsafeOutput(userInput); } </script> </body> </html> ``` ### XSS Detection Script ```javascript // scripts/javascript/xss-detector.js class XSSDetector { constructor() { this.payloads = [ '<script>alert(1)</script>', '<img src=x onerror=alert(1)>', '<svg onload=alert(1)>', 'javascript:alert(1)', '<iframe src="javascript:alert(1)">', '<body onload=alert(1)>', '<input autofocus onfocus=alert(1)>', '"><script>alert(1)</script>' ]; } testEndpoint(url, params) { console.log(`Testing: ${url}`); this.payloads.forEach((payload, index) => { const testParams = { ...params, test: payload }; const queryString = new URLSearchParams(testParams).toString(); const testUrl = `${url}?${queryString}`; console.log(`[${index + 1}] Payload: ${payload}`); console.log(` URL: ${testUrl}`); }); } sanitizeInput(input) { const element = document.createElement('div'); element.textContent = input; return element.innerHTML; } validateOutput(html) { const dangerous = /<script|javascript:|onerror=|onload=/i; return !dangerous.test(html); } } // Usage const detector = new XSSDetector(); detector.testEndpoint('http://localhost:8000/test.php', { user: 'testuser' }); // Sanitization example const userInput = '<script>alert("xss")</script>'; const safe = detector.sanitizeInput(userInput); console.log('Sanitized:', safe); ``` ### DOM-Based XSS Analysis ```javascript // scripts/javascript/dom-xss-analyzer.js function analyzeDOMSinks() { const dangerousSinks = { 'innerHTML': document.querySelectorAll('[id]'), 'eval': 'eval() calls', 'setTimeout': 'setTimeout with string', 'setInterval': 'setInterval with string', 'document.write': 'document.write() calls', 'location': 'location manipulation' }; console.log('=== DOM XSS Sink Analysis ==='); // Check for innerHTML usage document.querySelectorAll('*').forEach(el => { const id = el.id; if (id) { console.log(`Found element with ID: ${id}`); console.log(` - Can be targeted via innerHTML`); } }); // Monitor location-based sources const sources = { 'location.href': window.location.href, 'location.search': window.location.search, 'location.hash': window.location.hash, 'document.referrer': document.referrer }; console.log('\n=== User-Controlled Sources ==='); Object.entries(sources).forEach(([name, value]) => { if (value) { console.log(`${name}: ${value}`); } }); } // Execute analysis analyzeDOMSinks(); ``` ## PHP Security Testing ### Input Validation Testing ```php <?php // scripts/php/input-validator.php class InputValidator { public static function testInputs() { $testCases = [ '<script>alert(1)</script>', '"><img src=x onerror=alert(1)>', "'; DROP TABLE users; --", '../../../etc/passwd', '${7*7}', '{{7*7}}' ]; echo "=== Input Validation Tests ===\n\n"; foreach ($testCases as $input) { echo "Testing: " . $input . "\n"; echo "Sanitized: " . self::sanitize($input) . "\n"; echo "Escaped: " . self::escape($input) . "\n\n"; } } public static function sanitize($input) { return htmlspecialchars($input, ENT_QUOTES, 'UTF-8'); } public static function escape($input) { return addslashes($input); } public static function validateEmail($email) { return filter_var($email, FILTER_VALIDATE_EMAIL); } public static function validateURL($url) { return filter_var($url, FILTER_VALIDATE_URL); } } // Run tests InputValidator::testInputs(); ?> ``` ### XSS Vulnerable Endpoint (Testing Only) ```php <?php // scripts/php/vulnerable-endpoint.php // WARNING: This is intentionally vulnerable for testing header('X-Frame-Options: DENY'); header('X-Content-Type-Options: nosniff'); $test_mode = getenv('ACIDRAIN_TEST_MODE'); if ($test_mode !== 'enabled') { die('Test mode must be explicitly enabled via ACIDRAIN_TEST_MODE=enabled'); } // Intentionally vulnerable for testing function displayUnsafe($input) { return "<div>User input: " . $input . "</div>"; } // Safe version for comparison function displaySafe($input) { return "<div>User input: " . htmlspecialchars($input, ENT_QUOTES, 'UTF-8') . "</div>"; } if (isset($_GET['unsafe'])) { echo displayUnsafe($_GET['unsafe']); } if (isset($_GET['safe'])) { echo displaySafe($_GET['safe']); } ?> ``` ### Secure Form Handler ```php <?php // scripts/php/secure-form-handler.php class SecureFormHandler { private $allowedFields = ['name', 'email', 'message']; private $errors = []; public function processForm($data) { $sanitized = []; foreach ($this->allowedFields as $field) { if (!isset($data[$field])) { $this->errors[] = "Missing field: $field"; continue; } $value = $data[$field]; // Sanitize $value = trim($value); $value = stripslashes($value); $value = htmlspecialchars($value, ENT_QUOTES, 'UTF-8'); // Validate if ($field === 'email' && !filter_var($value, FILTER_VALIDATE_EMAIL)) { $this->errors[] = "Invalid email format"; continue; } $sanitized[$field] = $value; } if (empty($this->errors)) { return ['success' => true, 'data' => $sanitized]; } return ['success' => false, 'errors' => $this->errors]; } public function getErrors() { return $this->errors; } } // Usage $handler = new SecureFormHandler(); $result = $handler->processForm($_POST); if ($result['success']) { // Process safe data $data = $result['data']; echo "Form processed successfully\n"; } else { echo "Errors:\n"; foreach ($result['errors'] as $error) { echo "- $error\n"; } } ?> ``` ## Configuration ### Environment Setup Create a `.env` file in the project root: ```bash # .env ACIDRAIN_TEST_MODE=enabled ACIDRAIN_TARGET_URL=http://localhost:8000 ACIDRAIN_LOG_LEVEL=debug ACIDRAIN_REPORT_DIR=./reports ``` Load environment variables in PHP: ```php <?php // Load configuration $dotenv = parse_ini_file('.env'); foreach ($dotenv as $key => $value) { putenv("$key=$value"); } $testMode = getenv('ACIDRAIN_TEST_MODE'); $targetUrl = getenv('ACIDRAIN_TARGET_URL'); ?> ``` ### Test Server Setup Start a PHP development server for testing: ```bash # Navigate to scripts directory cd scripts/php # Start server php -S localhost:8000 # Test endpoint curl "http://localhost:8000/vulnerable-endpoint.php?safe=<script>test</script>" ``` ## Common Testing Patterns ### XSS Reflection Testing ```javascript // Test for reflected XSS function testReflectedXSS(baseUrl, params) { const payloads = [ '<script>alert(document.domain)</script>', '<img src=x onerror=alert(1)>', '"><svg/onload=alert(1)>', 'javascript:alert(1)' ]; payloads.forEach(payload => { const testParams = { ...params, input: payload }; const url = `${baseUrl}?${new URLSearchParams(testParams)}`; console.log(`Testing URL: ${url}`); // In practice, use fetch or automated browser fetch(url) .then(response => response.text()) .then(html => { if (html.includes(payload)) { console.warn('⚠️ Potential XSS: Payload reflected'); } else { console.log('✓ Payload sanitized or filtered'); } }); }); } // Usage testReflectedXSS('http://localhost:8000/test.php', { user: 'test' }); ``` ### Stored XSS Testing
GitHub에서 보기
이 SKILL.md는 매우 커서 SkillsMP가 여기에는 첫 섹션만 미리 보여줍니다. GitHub에서 보기