Tracy

#4 / 2 rate

Tracy

600 users

2020-05-11

jacob.heath.ncc

Extension Information

5 star
50%
4 star
0%
3 star
50%
2 star
0%
1 star
0%

Supported Languages

Permissions

Description

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

There are many different ways to trigger XSS, especially considering the large number of frontend frameworks that have been made popular in the last few years. For example, some of the less traditional ways of exploiting XSS can be through:

* DOM clobbering
* DOM injection
* Frontend template injection
* Backend template injection
* Open redirects

These attack vectors are significantly different than traditional stored and reflected XSS cases and they require new tools for finding them effectively.

Many similar tools only look for server response reflection, however this is not very helpful if all output encoding is performed by the frontend. In order to really gain knowledge about all the true sinks of the application, we need a tool that grants us "X-ray vision into the DOM".

This extensions was written with the goal of eliminating XSS by assisting a penetration tester in identifying every source of input into an application and following that input to all of its sinks. These cases are documented and stored as references that can be used to identify the locations of potentially risky input.

Reviews

Mistah Mark
Mistah Mark

Initial Review: ---------------- Installs cleanly, loads fine, however there is not comphrensive documentation (yet) to explain what exactly its doing to help pentest a site. Very cryptic desc. of its functions. I will report back once i learn some more but you should have a very firm handle on XSS before using this

Emmanuel Odota
Emmanuel Odota

Quite the tool to look for XSS...a must have tool

Similar extensions

Bishop Vulnerability Scanner
Bishop Vulnerability Scanner

Jack Kingsman

ZoomEye Tools
ZoomEye Tools

knownseczoomeye

Display Access Keys
Display Access Keys

dharris

Untrusted Types for DevTools
Untrusted Types for DevTools

Thomas Orlita

HackBar
HackBar

0140454

CounterXSS
CounterXSS

playarun93

Breakbot
Breakbot

https://jacksbrain.com

YesWeHack VDP Finder
YesWeHack VDP Finder

acc+browserext

Vulners Web Scanner
Vulners Web Scanner

vankyver

Input hidden Monitor
Input hidden Monitor

Bohumil Beran

Plugin Vulnerabilities
Plugin Vulnerabilities

White Fir Design

Investigate with Lacework
Investigate with Lacework

Lacework