A tool to dig out xss vulnerabilities

xsshelp

I just wrote a tool to help mine XSS vulnerabilities when I have nothing to do (mainly because I am lazy and want to save trouble, I simply used a tool to implement a relatively easy-to-use idea for digging XSS every time)

xsshelp version: 1.0.0``Usage: [-ut] [-u url] [-t thread] [-h help]``Options:` `-h this help` `-t int``thread Num (default 8)` `-u string` `a target url(Please add http or https)

It was first written in python, the link is here: https://github.com/wa1ki0g/xsshelp-py

Download address

  • Link: https://pan.quark.cn/s/51daa03ecb22

  • https://github.com/wa1ki0g/xsshelp

`How to learn hacking & cyber security

As long as you like my article today, my private network security learning materials will be shared with you for free. Come and see what is available.

1. Learning roadmap

There are a lot of things to learn about attack and defense. I have written down the specific things you need to learn in the road map above. If you can complete them, you will have no problem getting a job or taking on a private job.

2. Video tutorial

Although there are many learning resources on the Internet, they are basically incomplete. This is an Internet security video tutorial I recorded myself. I have accompanying video explanations for every knowledge point in the roadmap above.

The content covers the study of network security laws, network security operations and other security assessments, penetration testing basics, detailed explanations of vulnerabilities, basic computer knowledge, etc. They are all must-know learning contents for getting started with network security.

(They are all packaged into one piece and cannot be expanded one by one. There are more than 300 episodes in total)

Due to limited space, only part of the information is displayed. You need to click on the link below to obtain it.

< strong> < strong> CSDN Gift Pack: “Introduction to Hacking & Network Security” “Level Learning Resource Pack” Free Sharing< /strong>< /strong>< /strong>< /strong>< /strong>

3. Technical documents and e-books

I also compiled the technical documents myself, including my experience and technical points in participating in large-scale network security operations, CTF, and digging SRC vulnerabilities. There are more than 200 e-books. Due to the sensitivity of the content, I will not display them one by one.

Due to limited space, only part of the information is displayed. You need to click on the link below to obtain it.

< strong> < strong> CSDN Gift Pack: “Introduction to Hacking & Network Security” “Level Learning Resource Pack” Free Sharing< /strong>< /strong>< /strong>< /strong>< /strong>

4. Toolkit, interview questions and source code

“If you want to do your job well, you must first sharpen your tools.” I have summarized dozens of the most popular hacking tools for everyone. The scope of coverage mainly focuses on information collection, Android hacking tools, automation tools, phishing, etc. Interested students should not miss it.

There is also the case source code and corresponding toolkit mentioned in my video, which you can take away if needed.

Due to limited space, only part of the information is displayed. You need to click on the link below to obtain it.

< strong> < strong> CSDN Gift Pack: “Introduction to Hacking & Network Security” “Level Learning Resource Pack” Free Sharing< /strong>< /strong>< /strong>< /strong>< /strong>

Finally, here are the interview questions about network security that I have compiled over the past few years. If you are looking for a job in network security, they will definitely help you a lot.

These questions are often encountered when interviewing Sangfor, Qi Anxin, Tencent or other major companies. If you have good questions or good insights, please share them.

Reference analysis: Sangfor official website, Qi’anxin official website, Freebuf, csdn, etc.

Content features: Clear organization and graphical representation to make it easier to understand.

Summary of content: Including intranet, operating system, protocol, penetration testing, security service, vulnerability, injection, XSS, CSRF, SSRF, file upload, file download, file inclusion, XXE, logical vulnerability, tools, SQLmap, NMAP, BP, MSF…

Due to limited space, only part of the information is displayed. You need to click on the link below to obtain it.

< strong> < strong> CSDN Gift Pack: “Introduction to Hacking & Network Security” “Level Learning Resource Pack” Free Sharing< /strong>< /strong>< /strong>< /strong>< /strong>