## Contributor - 0140454 - GitHub: https://github.com/0140454 - lebr0nli - GitHub: https://github.com/lebr0nli - boylin0 - GitHub: https://github.com/boylin0 - HSwift - GitHub: https://github.com/HSwift ## How to open it? 1. Open 'Developer tools' (Press F12 or Ctrl+Shift+I) 2. Switch to 'HackBar' tab 3. Enjoy it ## Features * Load * From tab (default) * From cURL command * Supported * HTTP methods * GET * POST * application/x-www-form-urlencoded * multipart/form-data * application/json * Request editing mode * Basic * Raw * Custom payload * For more information, please visit https://github.com/0140454/hackbar/blob/master/README.md * Auto Test * Common paths (Wordlist from dirsearch included) * SQLi * Dump all database names (MySQL, PostgreSQL) * Dump tables from database (MySQL, PostgreSQL) * Dump columns from database (MySQL, PostgreSQL) * Union select statement (MySQL, PostgreSQL) * Error-based injection statement (MySQL, PostgreSQL) * Dump in one shot payload (MySQL) * Reference: https://github.com/swisskyrepo/PayloadsAllTheThings * Dump current query payload (MySQL) * Reference: https://github.com/swisskyrepo/PayloadsAllTheThings * Space to Inline comment * XSS * Vue.js XSS payloads * Angular.js XSS payloads for strict CSP * Some snippets for CTF * Html encode/decode with hex/dec/entity name * String.fromCharCode encode/decode * LFI * PHP wrapper - Base64 * SSRF * AWS - IAM role name * SSTI * Jinja2 SSTI * Flask RCE Reference: https://twitter.com/realgam3/status/1184747565415358469 * Java SSTI * Shell * Python reverse shell cheatsheet * bash reverse shell cheatsheet * nc reverse shell cheatsheet * php reverse shell/web shell cheatsheet * Encoding * URL encode/decode * Base64 encode/decode * Hexadecimal encode/decode * Unicode encode/decode * Escape ASCII to hex/oct format * Hashing * MD5 * SHA1 * SHA256 * SHA384 * SHA512 ## Shortcuts * Load * Default: Alt + A * Split * Default: Alt + S * Execute * Default: Alt + X * Switch request editing mode * Default: Alt + M ## Third-party Libraries For more information, please visit https://github.com/0140454/hackbar#third-party-libraries
You can Follow the below Step By Step procedure to install the HackBar Chrome Extension to your Chrome Web browser.
It is the HackBar Chrome extension download link you can download and install Chrome Browser.
The all in one Red team extension for web pentester
鼠标上的情报专家。简化查询流程,提升分析效率。步刻科技有限公司出品
A HackBar for google chrome/firefox browser. Small tool for pentesting websercurity.
Is a free online tool to find open ports in your system. You can also test whether port forwarding is working or not.
FOFA Pro view
This extension tells if visited sites have vulnerability disclosure programs
ZoomEye Tools provides a variety of functions to assist the use of Zoomeye, including a proview host and many other functions
OWASP Penetration Testing Kit
XSS辅助工具
在网页的源代码或js中找到一些有趣的东西