Přidatki za Firefox Browser
  • Rozšěrjenja
  • Drasty
    • za Firefox
    • Słowniki a rěčne pakćiki
    • Druhe sydła wobhladowaka
    • Přidatki za Android
Přizjewić
Přehlad Tracy

Tracy wot Jake Heath

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

5 (4 reviews)5 (4 reviews)
6 wužiwarjow6 wužiwarjow
Trjebaće Firefox, zo byšće tute rozšěrjenje wužiwał
Firefox sćahnyć a rozšěrjenje wobstarać
Dataju sćahnyć

Metadaty rozšěrjenja

Fota wobrazowki
The web interface for viewing Tracy results.
Wo tutym rozšěrjenju
A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

There are many different ways to trigger XSS, especially considering the large number of frontend frameworks that have been made popular in the last few years. For example, some of the less traditional ways of exploiting XSS can be through:
  • DOM clobbering
  • DOM injection
  • Frontend template injection
  • Backend template injection
  • Open redirects

These attack vectors are significantly different than traditional stored and reflected XSS cases and they require new tools for finding them effectively.

Many similar tools only look for server response reflection, however this is not very helpful if all output encoding is performed by the frontend. In order to really gain knowledge about all the true sinks of the application, we need a tool that grants us "X-ray vision into the DOM".

This extensions was written with the goal of eliminating XSS by assisting a penetration tester in identifying every source of input into an application and following that input to all of its sinks. These cases are documented and stored as references that can be used to identify the locations of potentially risky input.
Z 5 wot 4 pohódnoćacych pohódnoćeny
Přizjewće so, zo byšće tute rozšěrjenje pohódnoćił
Hišće pohódnoćenja njejsu

Hwězdne pohódnoćenje je so składowało

5
4
4
0
3
0
2
0
1
0
4 pohódnoćenja čitać
Prawa a datyDalše informacije

Trěbne prawa:

  • Přistup k wašim datam za wšě websydła měć
Dalše informacije
Přidatkowe wotkazy
  • Sydło pomocy
  • E-mejlowa adresa pomocy
Wersija
0.9.2
Wulkosć
910,55 KB
Posledni raz zaktualizowany
4 χρόνια πριν (21 Μαϊ 2021)
Přiwuzne kategorije
  • Webwuwiwanje
  • Priwatnosć a wěstota
Licenca
Licenca MIT
Wersijowa historija
  • Wšě wersije pokazać
Zběrce přidać
Tutón přidatk zdźělić
Wjace rozšěrjenjow wot Jake Heath
  • Hišće pohódnoćenja njejsu

  • Hišće pohódnoćenja njejsu

  • Hišće pohódnoćenja njejsu

  • Hišće pohódnoćenja njejsu

  • Hišće pohódnoćenja njejsu

  • Hišće pohódnoćenja njejsu

K startowej stronje Mozilla

Přidatki

  • Wo
  • Blog přidatkow Firefox
  • Dźěłarnička rozšěrjenjow
  • Wuwiwarski róžk
  • Wuwiwarske prawidła
  • Blog zhromadźenstwa
  • Forum
  • Programowy zmylk zdźělić
  • Směrnica za pohódnoćenja

Wobhladowaki

  • Desktop
  • Mobile
  • Enterprise

Produkty

  • Browsers
  • VPN
  • Relay
  • Monitor
  • Pocket
  • Bluesky (@firefox.com)
  • Instagram (Firefox)
  • YouTube (firefoxchannel)
  • Priwatnosć
  • Placki
  • Prawniske

Jeli nic hinak zapisane, so wobsah na tutym sydle pod Creative Commons Attribution Share-Alike License v3.0 abo poždźišej wersiju licencuje.