{"repo":"0140454/hackbar","free":true,"listed":false,"github":"https://github.com/0140454/hackbar","clone":"git clone https://github.com/0140454/hackbar.git","description":"A browser extension for Penetration Testing","language":"Vue","stars":575,"topics":["hackbar","chrome","extension","chrome-extension","firefox","firefox-addon","firefox-extension"],"license":null,"category":"security-tools","readme_excerpt":"HackBar A browser extension for Penetration Testing. Available on Chrome Web Store and Firefox Add-ons. Requested Permissions - storage - Save theme preferences - scripting - Perform POST request - Run test function - webRequest - Remember request information - Listen finish event to clean up - declarativeNetRequest - Set HTTP header value based on settings Features - Load - From tab (default) - From cURL command - Supported - HTTP methods - GET - POST - application/x-www-form-urlencoded - multipart/form-data - application/json - Request editing mode - Basic - Raw - Custom payload - Auto Test - Common paths (Wordlist from dirsearch included) - SQLi - Dump all database names (MySQL, PostgreSQL, MSSQL) - Dump tables from database (MySQL, PostgreSQL, SQLite, MSSQL) - Dump columns from database (MySQL, PostgreSQL, SQLite, MSSQL) - Union select statement (MySQL, PostgreSQL, SQLite, MSSQL) - Error-based injection statement (MySQL, PostgreSQL, MSSQL) - Dump in one shot payload (MySQL) - Dump current query payload (MySQL) - Space to Inline comment - XSS - Vue.js XSS payloads - Angular.js XSS payloads for strict CSP - Some snippets for CTF - Html encode/decode with hex/dec/entity name - String.fromCharCode encode/decode - Helper function for converting payload with atob - LFI - PHP wrapper - Base64 - SSRF - AWS - IAM role name - SSTI - Jinja2 SSTI - \"From Flask config to RCE\" Reference - Java SSTI - Shell - Python reverse shell cheatsheet - sh(bash) reverse shell cheatsheet - nc(ncat)","default_branch":null,"files":null,"tree":[],"storefront":"/r/0140454","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/0140454/hackbar/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}