extimg

HackBar

featured Icon

Featured

A browser extension for Penetration Testing

4.24 (51)
Publisher: 0140454
Overview
Stats
Download
Reviews

Overview

What is HackBar?

A browser extension for Penetration Testing.

SCREENSHOT

Preview
screen shot
Preview
screen shot
Preview
screen shot
screen shot

SUMMARY

## Contributor

- 0140454
- GitHub: https://github.com/0140454
- lebr0nli
- GitHub: https://github.com/lebr0nli
- boylin0
- GitHub: https://github.com/boylin0
- HSwift
- GitHub: https://github.com/HSwift

## How to open it?

1. Open "Developer tools" (Press F12 or Ctrl+Shift+I)
2. Switch to "HackBar" tab
3. Enjoy it

## Features

* Load
* From tab (default)
* From cURL command

* Supported
* HTTP methods
* GET
* POST
* application/x-www-form-urlencoded
* multipart/form-data
* application/json
* Request editing mode
* Basic
* Raw
* Custom payload
* For more information, please visit https://github.com/0140454/hackbar/blob/master/README.md

* Auto Test
* Common paths (Wordlist from dirsearch included)

* SQLi
* Dump all database names (MySQL, PostgreSQL)
* Dump tables from database (MySQL, PostgreSQL)
* Dump columns from database (MySQL, PostgreSQL)
* Union select statement (MySQL, PostgreSQL)
* Error-based injection statement (MySQL, PostgreSQL)
* Dump in one shot payload (MySQL)
* Reference: https://github.com/swisskyrepo/PayloadsAllTheThings
* Dump current query payload (MySQL)
* Reference: https://github.com/swisskyrepo/PayloadsAllTheThings
* Space to Inline comment

* XSS
* Vue.js XSS payloads
* Angular.js XSS payloads for strict CSP
* Some snippets for CTF
* Html encode/decode with hex/dec/entity name
* String.fromCharCode encode/decode

* LFI
* PHP wrapper - Base64

* SSRF
* AWS - IAM role name

* SSTI
* Jinja2 SSTI
* Flask RCE Reference: https://twitter.com/realgam3/status/1184747565415358469
* Java SSTI

* Shell
* Python reverse shell cheatsheet
* bash reverse shell cheatsheet
* nc reverse shell cheatsheet
* php reverse shell/web shell cheatsheet

* Encoding
* URL encode/decode
* Base64 encode/decode
* Hexadecimal encode/decode
* Unicode encode/decode
* Escape ASCII to hex/oct format

* Hashing
* MD5
* SHA1
* SHA256
* SHA384
* SHA512

## Shortcuts

* Load
* Default: Alt + A

* Split
* Default: Alt + S

* Execute
* Default: Alt + X

* Switch request editing mode
* Default: Alt + M

## Third-party Libraries

For more information, please visit https://github.com/0140454/hackbar#third-party-libraries

See More

Stats

15 Days

Trends for HackBar:

Rank

#0
--

User count

#
--

Category Rank

#
--

Rating

#4.24
--

Download

The latest version of HackBar is available on the Chrome web and is currently being used by 70,000 active users. The initial version was launched on 2020-05-29.

Total Downloads:  0(Downloads from CRX Insider)

HOW TO INSTALL HackBar FROM A CRX FILE

  1. Download HackBar CRX file
  2. NOTE: Sometimes the browser may block downloading / installing CRX file from outside the Chrome Web Store. If so, you may need to download the ZIP file instead
  3. In the URL bar, go to chrome://extensions
  4. Enable Developer mode
Show more

Ratings

4.24

Average Rating

Total ratings

51

USER REVIEWS (0)

No reviews
SIMILAR EXTENSIONS
Here are some Chrome extensions that are similar to HackBar Prompt List: