Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.
This tool is designed to help hackers identify and exploit cross-site scripting (XSS) vulnerabilities in web applications. XSS vulnerabilities occur when an application includes user-supplied data in its responses without properly sanitizing it, allowing an attacker to inject malicious code into...
xssexp
Cross-Site-Scripting (XSS) Automatic Scanner
Description
This tool is designed to test for xss vulnerabilities in web sites, it uses a list of payloads to inject into parameters and check to see if they get reflected back.
Hidden content
Purpose
toxssin is an open-source penetration testing tool that automates the process of exploiting Cross-Site Scripting (XSS) vulnerabilities. It consists of an https server that works as an interpreter for the traffic generated by the malicious JavaScript payload that powers this tool...
What is DalFox
Just, XSS Scanning and Parameter Analysis tool. I previously developed XSpear, a Ruby-based XSS tool, and this time, a full change occurred during the process of porting with golang!!! and created it as a new project. The basic concept is to analyze parameters, find XSS, and...
xsstools
xsstools is an xss development framework, with the goal of making payload writing easier.
Exfiltrators
A collection of exfiltrators is available
message: use postMessage
get: use fetch GET
post: use fetch POST urlencoded
postJSON: use fetch POST json encoded
...
XSSTRON
Electron JS Browser To Find XSS Vulnerabilities
Powerful Chromium Browser to find XSS Vulnerabilities automatically while browsing the web, it can detect many case scenarios with support for POST requests too.
Hidden content
JSshell – a JavaScript reverse shell. This using to exploit XSS remotely, help to find blind XSS, …
This tool works for both Unix and Windows operating system and it can be running with both Python 2 and Python 3. This is a big update of JShell – a tool to get a JavaScript shell with XSS by...
PwnXSS
A powerful XSS scanner made in python 3.7.
Main features
crawling all links on a website ( crawler engine )
POST and GET forms are supported
many settings that can be customized
Advanced error handling
Multiprocessing support.✔️
ETC…
Hidden content
Features
Support url encoding bypass
Support unicode encoding of HTML tag attribute value to bypass
Support HTML encoding to bypass the HTML tag attribute value
Support for flexible replacement of () '"to bypass
Case bypass
Hidden content
XSS-Freak
XSS-Freak is an XSS scanner fully written in python3 from scratch. It is one of its kind since it crawls the website for all possible links and directories to expand its attack scope. Then it searches them for input tags and then launches a bunch of XSS payloads. if an input is not...
NoXss
NoXss is a xss scanner, include reflected xss and dom-based xss.It can scan a single url or many urls from text file,also support to scan traffic from burpsuite.It has found some xss vulnerabilities in Bug Bounty program.
Features
Multi-process
Async request(use gevent)
...
Firefox Extension of HackBar without license
A HackBar for new firefox (Firefox Quantum). This addon is written in webextension and alternatives to the XUL version of original Hackbar.
How to use
Press F12 to open hackbar
Feature
Load, split, execute url from address bar...
A ready to use JSONP endpoints to help bypass content security policy of different websites.
The tool was presented during HackIT 2018 in Kiev. The presentation can be found Here
Hidden content
What is JSONBee ?
The main idea behind this tool is to find the JSONP endpoint(s) that would...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.