A Light Weight Tool for checking reflecting Parameters in a URL. Inspired by kxss by @tomnomnom.
go get -u github.com/KathanP19/Gxss
If the above step doesn’t work then you can try pre-built binary file from here
_____ __ __ _____ _____
| __| | | __| __|
| | |- -|__ |__ |
3.0 - @KathanP19
Usage of Gxss:
Set the Concurrency (default 50)
Set Custom Header.
Save Result to OutputFile
Payload you want to Send to Check Reflection (default "Gxss")
Set Custom User agent. Default is Mozilla (default "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36")
-v Verbose mode
It check for the reflected value on params one by one. (There are some tool like qsreplace which replace all params value but gxss checks payload one by one which makes it different from all those tools.)
Url is https://example.com/?p=first&q=second
First it will check if p param reflects
Then it will check if q param reflects
If reflection for any param is found it tells which param reflected in response.