Trending repositories for topic xss
serve as a reverse proxy to protect your web services from attacks and exploits.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
A list of resources for those interested in getting started in bug bounties
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Source code for Hacker101.com - a free online web and mobile security class.
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
Google Dork List - Uncover the Hidden Gems of the Internet ( There are at least 320+ categories )
A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
serve as a reverse proxy to protect your web services from attacks and exploits.
Google Dork List - Uncover the Hidden Gems of the Internet ( There are at least 320+ categories )
A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
A list of resources for those interested in getting started in bug bounties
Source code for Hacker101.com - a free online web and mobile security class.
serve as a reverse proxy to protect your web services from attacks and exploits.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
A list of resources for those interested in getting started in bug bounties
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Source code for Hacker101.com - a free online web and mobile security class.
Google Dork List - Uncover the Hidden Gems of the Internet ( There are at least 320+ categories )
INE/eLearnSecurity Web Application Penetration Tester (eWPTv2) Notes
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
🛡 Automatically configure your app to follow OWASP security patterns and principles by using HTTP Headers and Middleware
INE/eLearnSecurity Web Application Penetration Tester (eWPTv2) Notes
Google Dork List - Uncover the Hidden Gems of the Internet ( There are at least 320+ categories )
Beyond XSS: Explore the Web Front-end Security Universe. A series about front-end security
serve as a reverse proxy to protect your web services from attacks and exploits.
A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
🛡 Automatically configure your app to follow OWASP security patterns and principles by using HTTP Headers and Middleware
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
A big list of Android Hackerone disclosed reports and other resources.
serve as a reverse proxy to protect your web services from attacks and exploits.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
A list of resources for those interested in getting started in bug bounties
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Source code for Hacker101.com - a free online web and mobile security class.
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
Burp Suite Certified Practitioner Exam Study
bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
lamp-cloud 支持jdk21、jdk17、jdk11、jdk8,ta基于 SpringCloud + SpringBoot 开发的微服务中后台快速开发平台,专注于多租户(SaaS架构)解决方案,亦可作为普通项目(非SaaS架构)的基础开发框架使用,目前已实现插拔式数据库隔离、SCHEMA隔离、字段隔离 等租户隔离方案。
A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
Google Dork List - Uncover the Hidden Gems of the Internet ( There are at least 320+ categories )
🛡 Automatically configure your app to follow OWASP security patterns and principles by using HTTP Headers and Middleware
Open Source XSS exploitation tool. using http proxy to access the browser which executed js. [Engineering Experimental]
INE/eLearnSecurity Web Application Penetration Tester (eWPTv2) Notes
serve as a reverse proxy to protect your web services from attacks and exploits.
Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects.
Beyond XSS: Explore the Web Front-end Security Universe. A series about front-end security
A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
DOM Clobbering Wiki, Browser Testing, and Payload Generation
🔥 Repo related to my FrontendMasters course. An Advanced Web Dev Quiz that covers a wide range of the things web devs get to deal with on a daily basis.
Dork Search , Vulnerability Scanner ,SQL Injection , XSS , LFI ,RFI
functions to exploit common web application vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), Server-Side Request Forgery (SSRF), and Path Traversal.
Google Dork List - Uncover the Hidden Gems of the Internet ( There are at least 320+ categories )
A powerful bash script for massive XSS scanning leveraging Brute Logic's KNOXSS API
Find All Parameters - Tool to crawl pages, find potential parameters and generate a custom target parameter wordlist
🚀 XSSFUZZ - A tool for detecting XSS vulnerabilities in web applications.
A powerful bash script for massive XSS scanning leveraging Brute Logic's KNOXSS API
INE/eLearnSecurity Web Application Penetration Tester (eWPTv2) Notes
Open Source XSS exploitation tool. using http proxy to access the browser which executed js. [Engineering Experimental]
serve as a reverse proxy to protect your web services from attacks and exploits.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
A list of resources for those interested in getting started in bug bounties
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Source code for Hacker101.com - a free online web and mobile security class.
bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
lamp-cloud 支持jdk21、jdk17、jdk11、jdk8,ta基于 SpringCloud + SpringBoot 开发的微服务中后台快速开发平台,专注于多租户(SaaS架构)解决方案,亦可作为普通项目(非SaaS架构)的基础开发框架使用,目前已实现插拔式数据库隔离、SCHEMA隔离、字段隔离 等租户隔离方案。
Google Dork List - Uncover the Hidden Gems of the Internet ( There are at least 320+ categories )
Find All Parameters - Tool to crawl pages, find potential parameters and generate a custom target parameter wordlist
Burp Suite Certified Practitioner Exam Study
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
🛡 Automatically configure your app to follow OWASP security patterns and principles by using HTTP Headers and Middleware
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
Find All Parameters - Tool to crawl pages, find potential parameters and generate a custom target parameter wordlist
Open Source XSS exploitation tool. using http proxy to access the browser which executed js. [Engineering Experimental]
A powerful bash script for massive XSS scanning leveraging Brute Logic's KNOXSS API
A powerful asynchronous XSS scanner supporting up to 1,500 concurrent requests.
Google Dork List - Uncover the Hidden Gems of the Internet ( There are at least 320+ categories )
Beyond XSS: Explore the Web Front-end Security Universe. A series about front-end security
Cross-Site Scripting (XSS) injects malicious scripts into trusted websites via user input. Attacker-sent scripts run in users' browsers, accessing sensitive data, cookies, and even altering HTML conte...
[V5] This will help you setup a grabber with the following features: History, Passwords, Tokens, Cookies, Emails, IP Adresses, Roblox Login Information, Windows Keys, Computer Information.
List of every possible vulnerabilities in computer security.
🔥 Repo related to my FrontendMasters course. An Advanced Web Dev Quiz that covers a wide range of the things web devs get to deal with on a daily basis.
serve as a reverse proxy to protect your web services from attacks and exploits.
Diccionarios de: usuarios, passwords, XSS, Dorks, etc .. ( hackingyseguridad.com )