<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Articles on Enigma Writeups</title><link>https://enigma522.github.io/posts/articles/</link><description>Recent content in Articles on Enigma Writeups</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright> Made with 🧠 and ☕ by Enigma | &lt;a href="https://creativecommons.org/licenses/by-nc/4.0/" target="_blank" rel="noopener">CC BY-NC 4.0&lt;/a></copyright><lastBuildDate>Fri, 21 Nov 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://enigma522.github.io/posts/articles/index.xml" rel="self" type="application/rss+xml"/><item><title>Nuclei: The Sniper of Vulnerability Scanners</title><link>https://enigma522.github.io/posts/articles/nuclei/</link><pubDate>Fri, 21 Nov 2025 00:00:00 +0000</pubDate><guid>https://enigma522.github.io/posts/articles/nuclei/</guid><description>A beginner-friendly guide to using Nuclei, writing custom XSS fuzzing templates, and integrating it with Burp Suite.</description><content type="html"><![CDATA[<meta http-equiv="content-type" content="text/html; charset=utf-8"><img src="https://opengraph.githubassets.com/edd0bf0b7e3eb9c128b3ae96ac74cb891b89b99a735e49133692888d04062ee5/projectdiscovery/nuclei" jsaction="" class="sFlh5c FyHeAf iPVvYb" style="max-width: 1200px; height: 180px; margin: 4px 0px; width: 359px;" alt="GitHub - projectdiscovery/nuclei: Nuclei is a fast, customizable  vulnerability scanner powered by the global security community and built on  a simple YAML-based DSL, enabling collaboration to tackle trending  vulnerabilities on the internet." jsname="kn3ccd">
<h2 id="what-is-nuclei">What is Nuclei?</h2>
<p>Nuclei is a fast, open-source vulnerability scanner built by the folks at ProjectDiscovery.</p>
<p>If you&rsquo;ve used traditional scanners, you know they usually work like a &ldquo;shotgun&rdquo;—firing a massive, hard-coded database of checks at a target and hoping something hits. This often results in a lot of noise, slow scans, and false positives.</p>
<p><strong>Nuclei is different.</strong> It acts more like a <strong>&ldquo;sniper.&rdquo;</strong> It is entirely template-based, meaning it uses simple YAML files to describe exactly how to detect a specific vulnerability. This allows you to send precise requests to detect specific bugs (like a brand-new CVE) across thousands of hosts in minutes, without the mess of a generic scan.</p>
<p><strong>Why people love it:</strong></p>
<ul>
<li><strong>It&rsquo;s fast:</strong> Built in Go, it handles parallel scanning effortlessly.</li>
<li><strong>Community Powered:</strong> The security community writes and updates templates constantly. Often, a template for a new CVE is available within hours of its disclosure.</li>
</ul>
<h2 id="how-can-i-use-nuclei-basic-usage">How can I use Nuclei? (Basic Usage)</h2>
<p>Once you have Nuclei installed (usually via Go or a binary), you run it directly from the command line. Here are the essentials:</p>
<p><strong>1. Scan a Single Target</strong>
This scans <code>example.com</code> using the default list of community templates.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>nuclei -u https://example.com
</span></span></code></pre></div><ol start="2">
<li>Scan a List of Targets If you have a file urls.txt with many domains, Nuclei handles them in parallel.</li>
</ol>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>nuclei -l urls.txt
</span></span></code></pre></div><ol start="3">
<li>Use Specific Templates To avoid scanning for everything, you can specify a template or a folder of templates (e.g., only looking for CVEs or misconfigurations).</li>
</ol>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>nuclei -u https://example.com -t cves/ -t misconfiguration/
</span></span></code></pre></div><h2 id="writing-a-custom-template-to-detect-xss">Writing a Custom Template to Detect XSS</h2>
<p>One of Nuclei&rsquo;s coolest features is its extensibility. You aren&rsquo;t limited to the default list of vulnerabilities provided by the community.</p>
<p>Nuclei allows you to write your own YAML templates, giving you the freedom to create custom test scenarios, reproduce specific bug bounty findings, or build regression tests for your own applications.</p>
<p>Let’s get our hands dirty and write a template that uses DAST capabilities to &ldquo;fuzz&rdquo; a URL and find Reflected XSS.</p>
<h4 id="the-full-template">The Full Template</h4>
<p>Here is the complete code for xss.yaml. Don&rsquo;t worry, we&rsquo;ll break it down below.</p>
<pre tabindex="0"><code>id: reflected-xss

info:
  name: Reflected XSS
  author: Enigma522
  severity: medium
  tags: xss,dast
  description: Find Ref XSS in query params
  reference: github


http:
  - payloads:
      xss:
        - &#34;&lt;img src=1 onerror=eval(atob(&#39;YWxlcnQoJ1hTUycp&#39;))&gt;&#34;
        - &#34;&lt;script&gt;alert(1)&lt;/script&gt;&#34;
        - &#34;&#39;\&#34;&gt;&lt;img src=x&gt;&#34; 
    
    fuzzing:
      - part: query
        mode: single
        fuzz: 
          - &#34;{{xss}}&#34;

    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - &#34;{{xss}}&#34;

      - type: word
        part: content_type
        words:
          - &#34;text/html&#34;
</code></pre><p>you can find the template here
<a href="https://github.com/enigma522/nuclei-templates">https://github.com/enigma522/nuclei-templates</a></p>
<h4 id="lets-break-it-down">Let&rsquo;s Break It Down</h4>
<ol>
<li><strong>The Metadata</strong> First, we need to give our template an identity.</li>
</ol>
<pre tabindex="0"><code>id: reflected-xss

info:
  name: Reflected XSS
  author: Enigma522
  severity: medium
  tags: xss,dast
  description: Find Ref XSS in query params
  reference: github
</code></pre><ol start="2">
<li><strong>The Protocol &amp; Payloads</strong> Nuclei supports multiple protocols (DNS, FILE, TCP), but we are using http. Here, we define a list variable named xss that contains the malicious strings (payloads) we want to inject.</li>
</ol>
<pre tabindex="0"><code>http:
  - payloads:
      xss:
        - &#34;&lt;img src=1 onerror=eval(atob(&#39;YWxlcnQoJ1hTUycp&#39;))&gt;&#34;
        - &#34;&lt;script&gt;alert(1)&lt;/script&gt;&#34;
        - &#34;&#39;\&#34;&gt;&lt;img src=x&gt;&#34; 
</code></pre><ol start="3">
<li><strong>The Fuzzing Engine</strong> This is where the magic happens. We tell Nuclei to look at the query part of the URL (the stuff after ? like ?id=1).</li>
</ol>
<ul>
<li>mode: single: Tells Nuclei to replace parameters one by one.</li>
<li>fuzz: Tells it to replace the original value with our {{xss}} payloads defined above.</li>
</ul>
<pre tabindex="0"><code>    fuzzing:
      - part: query
        mode: single
        fuzz: 
          - &#34;{{xss}}&#34;
</code></pre><ol start="4">
<li><strong>The Matchers</strong> (Success Condition) Finally, how do we know if it worked? We use Matchers. To avoid false positives, we use matchers-condition: and. This means Nuclei will only report a vulnerability if BOTH of these things happen:</li>
</ol>
<ul>
<li>The exact payload ({{xss}}) is reflected back in the response body.</li>
<li>The response header content_type is text/html (because XSS won&rsquo;t trigger in a JSON or Plain Text file).</li>
</ul>
<p>We also added <code>stop-at-first-match: true</code> so the scan stops immediately after finding one vulnerability, saving time.</p>
<pre tabindex="0"><code>    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - &#34;{{xss}}&#34;

      - type: word
        part: content_type
        words:
          - &#34;text/html&#34;
</code></pre><h4 id="running-the-scan">Running the Scan</h4>
<p>To run this template, we will use the -dast flag. This flag is specifically designed to enable and run fuzzing capabilities within Nuclei.</p>
<p><img alt="alt text" src="../../../images/articles/nuclei/image.png"></p>
<p><img alt="alt text" src="../../../images/articles/nuclei/image1.png"></p>
<p>if the target is vulnerable, Nuclei will print the result in the terminal, showing exactly which payload triggered the XSS!</p>
<h2 id="integrating-with-burp-suite">Integrating with Burp Suite</h2>
<p>If you live inside Burp Suite like most pentesters, you don&rsquo;t have to constantly switch to the terminal.</p>
<p>Here is how to set it up:</p>
<ol>
<li>The Prerequisite: Jython Since this extension is written in Python, Burp needs an interpreter to run it.</li>
</ol>
<ul>
<li>Download the Jython Standalone JAR file.</li>
<li>In Burp, go to Extensions &gt; Settings &gt; Python Environment.</li>
<li>Select the JAR file you just downloaded.</li>
</ul>
<p><img alt="alt text" src="../../../images/articles/nuclei/jython.png"></p>
<p>Install the Extension Head over to the Extensions tab (formerly BApp Store), search for &ldquo;Nuclei Burp Integration,&rdquo; and hit install.</p>
<p><img alt="alt text" src="../../../images/articles/nuclei/burp.png"></p>
<p>Now we can configure it to use our custom templates by setting the path of our custom templates</p>
<p><img alt="alt text" src="../../../images/articles/nuclei/config.png"></p>
<p>Then we can simply use it from repeater</p>
<p><img alt="alt text" src="../../../images/articles/nuclei/repeater.png"></p>
<p><img alt="alt text" src="../../../images/articles/nuclei/xss.png"></p>
<p>Happy Hacking!</p>
]]></content></item></channel></rss>