Ferzjeskiednis fan Eval Villain - 24 ferzjes
Eval Villain troch bemodtwz
Wês foarsichtich mei âlde ferzjes! Dizze ferzjes wurde foar test- en referinsjedoeleinen werjûn.Jo moatte altyd de meast resinte ferzje fan in add-on brûke.
Nijste ferzje
Ferzje 2.11
Utjûn op 13 nov. 2024 - 53,89 KBWurket mei firefox 58.0 en letterFixes bug where localStorage is not properly sourced
Improves encoder function for path search
Fixes mistake is sourcer debug statmentBoarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Firefox downloade en de útwreiding ûntfangeJo hawwe Firefox nedich om dizze útwreiding te brûkenAldere ferzjes
Ferzje 2.10
Utjûn op 11 nov. 2024 - 53,74 KBWurket mei firefox 58.0 en letter* Copy Eval Villain Injection or Config from the configuration page and paste into any JavaScript file to get Eval Villain into other browsers or contexts.
* Better defaults for actual testing. Including CSPT and postMessage sinks.
* Set limits on source banks in the configuration page
* Lots of refactoringBoarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 2.9
Utjûn op 22 sep. 2023 - 41,75 KBWurket mei firefox 48.0 en letter* Use evSourcer to dynamically add to sources via instrumentation.
* Use evSinker as a dynamic sink to be used with instrumentation.
* EV now warns when it fails to load in a frame.
* Replace console.log with console.info in the web page to avoid the pages logs cluttering up Eval Villain output.Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 2.8
Utjûn op 9 mrt. 2023 - 40,88 KBWurket mei firefox 48.0 en letterFix output of regex needles without global flagBoarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 2.7
Utjûn op 6 feb. 2022 - 40,87 KBWurket mei firefox 59.0 en letterAdd function URLSearchParams.get to default config, disabled by default
Spelling fixes
Fix scope to preventing vars leaking into `window`Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 2.6
Utjûn op 26 jul. 2021 - 41,02 KBWurket mei firefox 59.0 en letterConstructors (like `new Function`) are now hooked.
Better proto hooking (like `value(Range.createContextualFragment)`).Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 2.5
Utjûn op 28 apr. 2021 - 40,82 KBWurket mei firefox 59.0 en letterFix bug where you couldn't delete a config item
Provided encoder function will provide a second parameter now, using `encoder("payload", true)` should cause the payload to be inserted into the DOM XSS source.Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 2.4
Utjûn op 15 apr. 2021 - 40,57 KBWurket mei firefox 59.0 en letterFix minor bug for configuration name collisionsBoarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 2.3
Utjûn op 13 apr. 2021 - 40,48 KBWurket mei firefox 59.0 en letter* When a encoded source is found in a sink, a encoding function in JavaScript will be printed to the console. This function lets you see how Eval Villain decoded the source, and lets you quickly encode your own payloads.
* Large text will receive it's own closed console.group to improve readability.Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 2.2
Utjûn op 26 jan. 2021 - 41,24 KBWurket mei firefox 59.0 en letter2 Major Changes
* EV will now recursively decode DOM XSS sources for URL, base64 and JSON encoding. Decoded values will then be used to search input to the hooked functions.
* Blacklists were previously applied to all input. I found this to be mostly useless. Now blacklists are applied to decoded input sources. So you can blacklist `/^true$/` and a URL parameter that is set to `true` won't cause all `eval` calls containing `true` to be marked as interesting.Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 2.1
Utjûn op 14 jul. 2020 - 41,25 KBWurket mei firefox 59.0 en letterIt is now safe to hook decodeURI, and decodeURIComponent. This can be helpful for finding where inputs are parsed.Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 2.0
Utjûn op 9 mrt. 2020 - 41,22 KBWurket mei firefox 59.0 en letterRefactoring should improve speed and performance.
Monitors sinks for window nameBoarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.11
Utjûn op 22 aug. 2019 - 40,49 KBWurket mei firefox 59.0 en letterTypes: enable/disable types that you are interested.Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.10
Utjûn op 6 aug. 2019 - 40,17 KBWurket mei firefox 59.0 en letterUsing `Reflect.apply` for proxying to reduce bugs. Thanks Mike Samuel!
Show argument types
Better handling of multiple arguments to a function.Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.9
Utjûn op 25 jun. 2019 - 40,01 KBWurket mei firefox 59.0 en letterFeatures:
* Toggle Eval Villain with key commands
Bug fixes:
Functions are now hooked using `Proxy`. Eval Villain should break fewer pages. Reference: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/ProxyBoarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.8
Utjûn op 13 jun. 2019 - 40,07 KBWurket mei firefox 59.0 en letterURL Decode bug fixBoarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.7
Utjûn op 11 jun. 2019 - 40,01 KBWurket mei firefox 59.0 en letterFixed bug in query searchBoarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.6
Utjûn op 11 jun. 2019 - 40,01 KBWurket mei firefox 59.0 en letterFunction hooks now handle multiple arguments
Hook `Function` if you want, likely to break webpages though
Bug fixes/improved query searchBoarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.5
Utjûn op 2 jan. 2019 - 36,47 KBWurket mei firefox 59.0 en letterHandles malformed URI encoding without breaking code flow.
Having console.log remapped by the page should no longer interfere with output.Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.4
Utjûn op 14 aug. 2018 - 36,4 KBWurket mei firefox 59.0 en letter, android 59.0 oant 68.** fix URL decode logic bug
* No longer search for URL parameter names.Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.3
Utjûn op 10 aug. 2018 - 36,41 KBWurket mei firefox 59.0 en letter, android 59.0 oant 68.** fixed a couple RegEx needle highlighting bugs
* fragment and query search now also check if the value has been URL decoded.Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.2
Utjûn op 7 aug. 2018 - 35,91 KBWurket mei firefox 59.0 en letter, android 59.0 oant 68.*This version just improves the UI some.Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.1
Utjûn op 2 aug. 2018 - 36,06 KBWurket mei firefox 59.0 en letter, android 59.0 oant 68.*Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0
Ferzje 1.0
Utjûn op 2 aug. 2018 - 36,07 KBWurket mei firefox 59.0 en letter, android 59.0 oant 68.*Boarnekoade frijjûn ûnder Allinnich GNU General Public License v3.0