XSSploit. Browser Exploitation Framework.
Control browsers "realtime" with JavaScript. Requires: MySQL, PHP and a webserver. (recommend HHVM and Nginx)
Features: Supports simple configuration of auto running any JavaScript on browser connect Logs all actions in MySQL Simple creation of custom modules in pure JavaScript The web / DB API < 500 lines of PHP code Supports polling via <script> tags Supports polling via XMLHttpRequest Supports obfuscated JavaScript via javascript-packer
Documentation: https://github.com/foneyop/xssploit/wiki
External Libraries: http://joliclic.free.fr/php/javascript-packer/en/
Development: Chrome module for searching for XSS vulnerabilities Chrome module includes MySQL support for logging
Do What Thou Willt.