dictionaries
Misc dictionaries for directory/file enumeration, username enumeration, password dictionary/bruteforce attacks (by bl4de)
AwesomeXSS
Awesome XSS stuff (by s0md3v)
dictionaries | AwesomeXSS | |
---|---|---|
1 | 2 | |
221 | 4,655 | |
- | - | |
4.7 | 2.7 | |
13 days ago | 29 days ago | |
Python | JavaScript | |
- | MIT License |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
dictionaries
Posts with mentions or reviews of dictionaries.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-11-15.
AwesomeXSS
Posts with mentions or reviews of AwesomeXSS.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-11-15.
-
A Summary of Fuzzing Tools and Dictionaries For Bug Bounty Hunters
AwesomeXSS https://github.com/s0md3v/AwesomeXSS
-
Filter bypass
You don't need to use alert. You can try using confirm(). If the website is blocking javascript, you can try to capitalize some letters, something like jAvAscRiPt:confirm(1). You can check this repo, it's a gold mine of xss content.
What are some alternatives?
When comparing dictionaries and AwesomeXSS you can also consider the following projects:
bugbounty-cheatsheet - A list of interesting payloads, tips and tricks for bug bounty hunters.
OneListForAll - Rockyou for web fuzzing
fuzzdb - Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
xss-payload-list - 🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
big-list-of-naughty-strings - The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.