My-Methodologies/xss/README.md

21 lines
759 B
Markdown
Raw Normal View History

2023-05-06 23:28:49 +05:30
## Get Parameter as much as possible
1. https://github.com/devanshbatham/ParamSpider
2. gospider -S tageturls.txt -c 10 -d 5 --blacklist ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|ico|pdf|svg|txt)" --other-source | grep -e "code-200" | awk '{print $5}'|grep "=" | qsreplace -a | dalfox pipe -o result.txt
2023-05-06 23:29:39 +05:30
3. Waybackurls | gau
4. https://github.com/s0md3v/Arjun
5. https://github.com/hakluke/hakrawler
2023-05-06 23:50:31 +05:30
6. https://github.com/PortSwigger/param-miner
2023-05-06 23:28:49 +05:30
Combine all in a file and remove duplicates.
## Run XSS fuzzer
1. https://github.com/s0md3v/XSStrike
2. https://github.com/hahwul/dalfox
2023-05-06 23:50:31 +05:30
Resources:
- https://blog.yeswehack.com/yeswerhackers/parameter-discovery-quick-guide-to-start/
- https://infosecwriteups.com/tale-of-my-first-xss-27f622bc47c0
2023-05-06 23:28:49 +05:30
<hr>