{"id":13843594,"url":"https://github.com/rewanthtammana/vuln-headers-extension","last_synced_at":"2026-01-12T13:04:50.397Z","repository":{"id":129193087,"uuid":"113659591","full_name":"rewanthtammana/vuln-headers-extension","owner":"rewanthtammana","description":"Firefox extension which parses the headers of all the requests which are being flowing through your firefox browser to detect for vulnerabilities.","archived":false,"fork":false,"pushed_at":"2018-10-28T07:17:51.000Z","size":261,"stargazers_count":60,"open_issues_count":0,"forks_count":19,"subscribers_count":7,"default_branch":"master","last_synced_at":"2024-10-29T16:58:11.406Z","etag":null,"topics":["extensions","firefox","firefox-extension","firefox-webextension","scanner"],"latest_commit_sha":null,"homepage":"https://medium.com/@rewanthcool/firefox-vuln-headers-extension-e848b6d80d14","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/rewanthtammana.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2017-12-09T10:02:03.000Z","updated_at":"2024-01-21T18:55:33.000Z","dependencies_parsed_at":null,"dependency_job_id":"e0599577-2081-40a3-87c6-90d68af45e3f","html_url":"https://github.com/rewanthtammana/vuln-headers-extension","commit_stats":null,"previous_names":[],"tags_count":2,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rewanthtammana%2Fvuln-headers-extension","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rewanthtammana%2Fvuln-headers-extension/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rewanthtammana%2Fvuln-headers-extension/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rewanthtammana%2Fvuln-headers-extension/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/rewanthtammana","download_url":"https://codeload.github.com/rewanthtammana/vuln-headers-extension/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225755037,"owners_count":17519190,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["extensions","firefox","firefox-extension","firefox-webextension","scanner"],"created_at":"2024-08-04T17:02:17.397Z","updated_at":"2026-01-12T13:04:50.385Z","avatar_url":"https://github.com/rewanthtammana.png","language":"JavaScript","funding_links":[],"categories":["JavaScript"],"sub_categories":[],"readme":"# vuln-headers-extension\n___\nThis is firefox extension which parses the requests before forwarding to the DNS server to scan for vulnerable URLs which occur due to [Headers](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers).\n\n## Highlights\n___\nThe extension currently detects URLs which are vulnerable to\n* CORS Misconfiguration\n* Host Header Injection\n* Missing X-XSS-Protection headers (commented in the code due to its low severity)\n* Clickjacking support\n\n## Achievements\n___\nSubmitted vulnerabilities to websites like #signup.com , #Chargify, #Hotstar, #Medium, etc using this tool.\nGot listed in #Chargify HOF and other organisaitons are resolving the issues.\n\n### Screenshots\n![https://raw.githubusercontent.com/rewanth1997/vuln-headers-extension/master/GUI.PNG](https://raw.githubusercontent.com/rewanth1997/vuln-headers-extension/master/GUI.PNG)\n\n### Installation\n___\n##### Method 1 -\n1. Clone the repo or fork it.\n2. Open Firefox and load `about:debugging` in the URL bar.\n3. Click the Load Temporary Add-on button and select the `manifest.json` file in your cloned repo.\n4. Now the vuln-headers-extension is installed.\n\n##### Method 2 -\n1. Clone the repo or fork it.\n2. Install the [web-ext](https://developer.mozilla.org/en-US/Add-ons/WebExtensions/Getting_started_with_web-ext) tool, a npm package.\n3. Change into the directory where you cloned the repo.\n4. Type `web-ext run`. This will launch Firefox and install the extension.\n\n### Using -\n1. Once you install the extension you can see an icon in the tool bar.\n2. Click on the icon and a new tab gets opened.\n3. Leave it open and do your browsing/work.\n4. The extension automatically logs all the vulnerable URLs to the new tab.\n5. Now you can submit a report to the respective organisaiton and make it more secure.\n\n### Contributing\nWant to add more features to it? **Fork the repo** and create a [Pull Request](https://help.github.com/articles/creating-a-pull-request/).\nLike this tool, **STAR** it and click on **Watch** to get more updates on this tool.\n\n#### Article\nhttps://medium.com/@rewanthcool/firefox-vuln-headers-extension-e848b6d80d14\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frewanthtammana%2Fvuln-headers-extension","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Frewanthtammana%2Fvuln-headers-extension","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frewanthtammana%2Fvuln-headers-extension/lists"}