#xss (27 Repositories)
Ranked open-source repositories tagged with #xss, scored by pull request acceptance likelihood and maintainer engagement velocity.
13.4%
14.2h
27 repositories tagged #xss
hahwul/dalfox
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
voku/anti-xss
㊙️ AntiXSS | Protection against Cross-site scripting (XSS) via PHP
mganss/HtmlSanitizer
Cleans HTML to avoid XSS attacks
cure53/DOMPurify
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
reddelexc/hackerone-reports
Top disclosed reports from HackerOne
botesjuan/Burp-Suite-Certified-Practitioner-Exam-Study
Burp Suite Certified Practitioner Exam Study
ericnorris/striptags
An implementation of PHP's strip_tags in Typescript.
kkomelin/isomorphic-dompurify
Use DOMPurify on server and client in the same way
chaitin/SafeLine
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
dr34mhacks/XSSNow
Find XSS payloads that actually work by filtering them based on real-world constraints instead of blind payload spraying.
dzonerzy/goWAPT
Go Web Application Penetration Test
AntSwordProject/ant
实时上线的 XSS 盲打平台
kleiton0x00/XSScope
XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.
DenisPodgurskii/pentestkit
OWASP PTK - application security browser extension.
dschadow/JavaSecurity
Java web and command line applications demonstrating various security topics
YalcinYolalan/WSSAT
WEB SERVICE SECURITY ASSESSMENT TOOL
dongfangyuxiao/BurpExtend
基于Burp插件开发打造渗透测试自动化
andreiverse/vaf
Vaf is a cross-platform very advanced and fast web fuzzer written in nim
s0md3v/XSStrike
Most advanced XSS scanner.
OWASP/Vulnerable-Web-Application
OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber
mazen160/xless
The Serverless Blind XSS App
tegal1337/0l4bs
Cross-site scripting labs for web application security enthusiasts
ImAyrix/fallparams
Find All Parameters - Tool to crawl pages, find potential parameters and generate a custom target parameter wordlist
YagamiiLight/Cerberus
一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
hackademix/noscript
The popular NoScript Security Suite browser extension.
chennqqi/godnslog
An exquisite dns&http log server for verify SSRF/XXE/RFI/RCE vulnerability
raz-varren/xsshell
An XSS reverse shell framework