![Hands-On Bug Hunting for Penetration Testers](https://wfqqreader-1252317822.image.myqcloud.com/cover/440/36699440/b_36699440.jpg)
Payload Processing
Here you'll want to add a rule, choosing Invoke Burp extension as the rule type and then XSS Validator as the processor:
![](https://epubservercos.yuewen.com/89F73A/19470388701539106/epubprivate/OEBPS/Images/14f52966-e892-4a81-8d76-abb9069d9860.png?sign=1738892812-fXwIStjJeH0OodTFUexjyo5nqjppYgs1-0-52b212e4db03254eb0a0f7ff94f655d2)
After you've made all these selections, your app's GUI should look like the following:
![](https://epubservercos.yuewen.com/89F73A/19470388701539106/epubprivate/OEBPS/Images/1623ec0d-c8fa-4f6b-9289-20a792bc4317.png?sign=1738892812-TLBMW7BJ1Lwky62pAHm2eLR4U6TBHuni-0-8642d872f957306947a36d89a6007310)
We need to make one more setting change before we can start our attack. If you head over to the xssValidator tab, you'll see a random string generated in the Grep Phrase field, and you might also spot the bullet point explaining that Successful attacks will be denoted by the presence of the Grep Phrase:
![](https://epubservercos.yuewen.com/89F73A/19470388701539106/epubprivate/OEBPS/Images/269239c1-2bbf-482d-8b1d-7091eab35aa9.png?sign=1738892812-pKfGYzNZjBaNVUpi1ZOfljY7YdmlPujd-0-24d87bd24bfd3307ab89bae0d02083b5)
We want to add that grep phrase into the Grep - Match section in the Options tab so that, when we're viewing our attack results, we can see a checkbox indicating whether our phrase turned up in an attack response:
![](https://epubservercos.yuewen.com/89F73A/19470388701539106/epubprivate/OEBPS/Images/c84b0785-1734-4bfd-ab95-ba08fd45a838.png?sign=1738892812-2mI0Kpmojuzitsnjvw4yeShhOn0pexpY-0-b14e70aafced372af9e2a9428ed6e0f0)
Once that phrase has been added, we're ready to start our attack. Click the start attack button in the top-right of the Options (and every other) view.
After clicking the button, you should see an attack window pop up and start to self-populate with the results of the XSS snippet submissions:
![](https://epubservercos.yuewen.com/89F73A/19470388701539106/epubprivate/OEBPS/Images/64e3a8d5-d639-40f1-b54e-b4eb4d7f2fbb.png?sign=1738892812-tGv8204uCnOC2dlpxGOUbZSLnfIRcjht-0-e206393d4ce0cf446ebd02d72fddcd0a)
And voila! We can see the presence of our grep phrase, meaning that our submissions have been a success, for several of the tag/attribute combinations generated by the XSS Validator submissions.