{"repo":"mastomii/nexss","free":true,"listed":false,"github":"https://github.com/mastomii/nexss","clone":"git clone https://github.com/mastomii/nexss.git","description":"NeXSS is a modern, self-hosted Blind XSS (Cross-Site Scripting) hunter and callback listener built with Next.js. It helps security researchers and penetration testers discover and validate blind XSS vulnerabilities by capturing detailed information when payloads execute on target systems.","language":"TypeScript","stars":34,"topics":["bugbounty","bughunting","cybersecurity","javascript","xss"],"license":"MIT","category":"security-tools","readme_excerpt":"Lightweight Blind XSS Listener Features • Installation • Usage • Configuration --- Description NeXSS is a modern, self-hosted Blind XSS (Cross-Site Scripting) hunter and callback listener built with Next.js. It helps security researchers and penetration testers discover and validate blind XSS vulnerabilities by capturing detailed information when payloads execute on target systems. When your XSS payload triggers on a vulnerable application, NeXSS captures comprehensive data including cookies, DOM content, screenshots, local/session storage, and more — all delivered to your dashboard in real-time with optional Telegram notifications. Dashboard with real-time statistics and recent reports Features Feature Description --------- ------------- Blind XSS Detection Automatically captures data when payloads execute Screenshot Capture Takes screenshots of the vulnerable page using html2canvas Cookie Extraction Captures all accessible cookies from the target DOM Capture Stores the full HTML content of the affected page Storage Extraction Captures localStorage and sessionStorage data Request Details Logs URL, origin, referer, user-agent, and IP address Persistent Sessions Maintain connection with compromised browsers for JS command execution Traffic Interception Observe HTTP requests/responses within victim's browser session Path Enumeration NEW - Automatically probe sensitive paths and capture responses Grouped View NEW - Organize reports by origin/domain for better analysis AES-256 En","default_branch":null,"files":null,"tree":[],"storefront":"/r/mastomii","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mastomii/nexss/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}