Source code for Hacker101.com - a free online web and mobile security class.
-
Updated
Jan 19, 2022 - SCSS
{{ message }}
Source code for Hacker101.com - a free online web and mobile security class.
Most advanced XSS scanner.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
A list of resources for those interested in getting started in bug bounties
一款完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档
lamp-cloud 基于Jdk11 + SpringCloud + SpringBoot的微服务快速开发平台,其中的可配置的SaaS功能尤其闪耀, 具备RBAC功能、网关统一鉴权、Xss防跨站攻击、自动代码生成、多种存储系统、分布式事务、分布式定时任务等多个模块,支持多业务系统并行开发, 支持多服务并行开发,可以作为后端服务的开发脚手架。代码简洁,注释齐全,架构清晰,非常适合学习和企业作为基础框架使用。
Awesome XSS stuff
Web Application Security Scanner Framework
Git All the Payloads! A collection of web attack payloads.
bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
XSS'OR - Hack with JavaScript.
Collection of quality safety articles. Awesome articles.
A container repository for my public web hacks!
A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
pentest framework
Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns
Advanced dork Search & Mass Exploit Scanner
A big list of Android Hackerone disclosed reports and other resources.
Add a description, image, and links to the xss topic page so that developers can more easily learn about it.
To associate your repository with the xss topic, visit your repo's landing page and select "manage topics."