Exploit-Me Known Issues

Current Issues

The Exploit-Me tools are not compatible with Firefox 3

Currently the exploit-me tools are not installable under Firefox 3 due to installation, API and security changes. We are working to rectify this issue and will hopefully have new versions of the tools soon which are usable under Firefox 3.

Resolved Issues

Incorrect Text in SQL Inject-Me Sidebar [Fixed in 0.2]

The SQL Inject-Me says that it is a Cross-Site Scripting tool in the sidebar blurb. This should be changed to say it is a SQL Injection tool.

XSS-Me Attack Patterns Reference Security Compass [Fixed in 0.2.1]

Some of the attack patterns in XSS-Me need to work off of an external source. Currently that source is set to Security Compass. This should be noted so people can change the pattern if desired.

Work Around

Open the Options for the XSS-Me. Go to the XSS Strings tab. Export the list of XSS strings. Edit the exported file and replace any securitycompass.com references with another site. Delete the list of XSS Strings from the Options tab. Import the edited list of strings.