But to my surprise it was quite useful in detecting XSS too. I was visiting a site I had previously detected XSS issue in it. As soon as the page loads the netcraft tool throws a message:
"The Page you are trying to visit is using Cross-Site Scripting(XSS).This is commonly used in Phishing Attack.Do you still want to go there?"
and then the site is categorized as Phishing site.




