TheHulk is a dynamic analysis tool designed to detect and exploit DOM Clobbering vulnerabilities.
☆95Aug 25, 2025Updated last year
Alternatives and similar repositories for TheHulk
Users that are interested in TheHulk are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A collection of client-side libraries with HTML injection vulnerabilities and DOM clobbering gadgets.☆49Aug 31, 2025Updated last year
- CSS injection requires an attacker to load a standalone CSS file to leak HTML tag attributes.☆21Apr 19, 2024Updated 2 years ago
- A fancier postMessage tracker with Chrome Manifest version V3 support and a few additional features, inspired by Frans Rosens postmessage…☆132Sep 12, 2025Updated last year
- jxscout superpowers JavaScript analysis for security researchers☆470Apr 12, 2026Updated 5 months ago
- Chrome extension for automating CSPT discovery☆162May 12, 2026Updated 4 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.☆818Dec 9, 2025Updated 9 months ago
- Find XS-Leaks in the browser by diffing DOM-Graphs in two states☆20Jun 24, 2026Updated 3 months ago
- Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities.☆241Jul 24, 2025Updated last year
- Your AI javascript collaborator☆44May 16, 2025Updated last year
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆57Oct 25, 2023Updated 2 years ago
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆151Dec 9, 2024Updated last year
- MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.☆300Oct 5, 2024Updated last year
- Code for our 2023 IEEE S&P Paper "The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the Web"☆16Jul 16, 2026Updated 2 months ago
- Adobe Experience Manager (AEM) hacking toolkit☆118Sep 26, 2025Updated 11 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ☆51Aug 2, 2025Updated last year
- Useful configurations for the DomLogger++ extension☆52Apr 7, 2026Updated 5 months ago
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆170Jul 2, 2024Updated 2 years ago
- This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) an…☆150Feb 4, 2026Updated 7 months ago
- Caido plugin for jxscout☆17Jul 7, 2026Updated 2 months ago
- XS-Leak Browser Test Suite☆89Aug 28, 2026Updated 3 weeks ago
- A command line Curses based json viewer and tabulator☆30Aug 3, 2025Updated last year
- Tool to parse subdomains from dmarc.live☆153Apr 19, 2024Updated 2 years ago
- Extension to log postMessage()☆17Feb 17, 2026Updated 7 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A web browser with dynamic data-flow tracking enabled in the Javascript engine and DOM, based on Mozilla Firefox (https://github.com/mozi…☆178Jul 29, 2026Updated last month
- Automated JavaScript Debugging Tool using CDP - Automatically sets breakpoints for specified strings/patterns in JavaScript code☆93Dec 22, 2024Updated last year
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆61Dec 18, 2025Updated 9 months ago
- Abuse trust-boundaries to bypass firewalls and network controls☆433Jul 10, 2026Updated 2 months ago
- Content-Type Research☆671Jun 29, 2025Updated last year
- ai-based domain name generation☆147May 7, 2026Updated 4 months ago
- Extract GraphQL operations from javascript☆25Mar 18, 2026Updated 6 months ago
- CVE-2025-0133 GlobalProtect XSS☆21Jun 17, 2025Updated last year
- ☆178Oct 15, 2024Updated last year
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications☆1,375Aug 7, 2025Updated last year
- Guided Differential Fuzzing for HTTP Request Parsing Discrepancies☆20Apr 11, 2024Updated 2 years ago
- EvenBetter is a frontend Caido plugin that makes the Caido experience even better 😎☆177May 15, 2026Updated 4 months ago
- Easily gather all routes related to a NextJs application through parsing of _buildManifest.js☆67Dec 12, 2022Updated 3 years ago
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆16Jul 17, 2024Updated 2 years ago
- HTML source files demonstrating HTML5 postmessage vulnerabilities☆20Jul 26, 2020Updated 6 years ago
- CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scr…☆718Aug 31, 2026Updated 3 weeks ago