{"repo":"mazen160/xless","free":true,"listed":false,"github":"https://github.com/mazen160/xless","clone":"git clone https://github.com/mazen160/xless.git","description":"The Serverless Blind XSS App","language":"JavaScript","stars":338,"topics":["xss","blind-xss","serverless","out-of-band","exfiltration","browser-exploitation"],"license":null,"category":"security-tools","readme_excerpt":"xless The Serverless Blind XSS App :information source: About The Project Xless is a serverless Blind XSS (bXSS) application that can be used to identify Blind XSS vulnerabilities using your own deployed version of the application. There is no need to run a full deployment process; just setup a vercel.com account and run bash deploy.sh . That's it. You now have a fully-running Blind XSS listener that uses Slack to notify you for callbacks. :warning: Requirements vercel.com account: Vercel provides a free plan for serverless. If you use another provider for serverless, code changes should be minimal. Slack Incoming Webhook URL. IMGBB (free) Account and API key - for the screenshots. :rocket: Deployment 1. Run bash deploy.sh 2. Use the URL for blind XSS testing :fire: Xless will automatically serve the XSS payload, collect information, and exfiltrate it into your serverless app, which is then sent right to you in Slack. :speech balloon: Example Payload :eyes: Demo :incoming envelope: Collected Data Cookies User-Agent HTTP Referrer Browser DOM Browser Time Document Location Origin LocalStorage SessionStorage IP Address Screenshot :satellite: Out-of-Band (OOB) Callbacks Listener Xless also works as an OOB (Out-of-Band) callbacks listener for HTTP/HTTPS requests. Any HTTP GET request that is sent to non-parent path will be alerted. :eyes: Demo Or anything random, such as: :man health worker: Health Check Xless provides a /health endpoint to let you know that everything is configur","default_branch":null,"files":null,"tree":[],"storefront":"/r/mazen160","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mazen160/xless/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}