Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
XnlReveal — A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements and enable disabled elements. | Kitploit
Tools/GitHubGitHub/xnl-h4ck3r/xnlreveal
OSINT (Open Source Intelligence)Web Vulnerability ScannersVulnerability AnalysisInformation GatheringWeb SecurityPenetration Testing
GitHubxnl-h4ck3r/xnlreveal

XnlReveal

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements and enable disabled elements.

View Repository
45162205 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

About - v4.5

This is a Chrome/Firefox Extension that can do the following:

  • For hosts that are in scope:
    • Show an alert for any query parameters that are reflected (and identify "sus" parameters).
    • Optionally check if the characters '," and < are reflected without being encoded.
    • Write details of reflected parameters to the browser DevTools Xnl Reveal tab.
    • Copy details of reflected parameters to the users clipboard.
    • Show the Wayback Archive endpoints (up to 1000) for the path visited (in the browser DevTools Xnl Reveal tab).
    • Show any hidden elements on the page.
    • Enable any disabled elements on the page.
  • Provide a context menu (regardless if extension is active or host is in scope) to:
    • Open a new tab to show Wayback endpoints for the current domain.
    • Show any hidden elements on the page (even if the extension isn't enabled to do automatically).
    • Enable any disabled element on the page (even if the extension isn't enabled to do automatically).
    • Open a new tab to show the Google Cache version of the current page.
    • Open a new tab to show the FOFA search results for the current domain.
    • Create a word list from the contents of a page in a new tab (currently only Chrome version only)
    • Add/Remove the current domain to the whitelist/blacklist.
  • Visually indicate if the Wayback CDX Server API is not available (regardless if extension is active).

The ability to show an alert for reflected parameters was inspired by a comment by @renniepak on Episode 42 of the Critical Thinking - Bug Bounty Podcast where he mentioned he had his own browser extension that let him know about any reflections.

The number of reflected parameters found is shown by a green badge on the extension icon. However, if any of the reflected parameter names are in a categories described in the "sus" parameters research by @Jhaddix and @G0LDEN_infosec then the badge will be red. If there are any "sus" parameters, then the categories will also be shown in the output to the DevTools Xnl Reveal tab, alert box and clipboard, e.g. boringParameter, query [XSS], path [LFI/RFI | SSRF | XSS] (this is the same as the "sus" parameters identification in my GAP Burp Extension).

The ability to show hidden elements, and enable disabled elements, was inspired by this Tweet by Critical Thinking - Bug Bounty Podcast and I initially created as browser bookmarks.

The extension icon is normally shown with a black background , but if the icon appears with a red background , then it indicates that the Wayback CDX Server API is probably unavailable. Even if the main features are disabled, the extension will check the status of the API every 10 minutes.
IMPORTANT: When using tools like waymore, waybackurls or gau to get URLs from the Wayback archive, it uses the CDX Server API. If the API is down, you will not be getting any data from the Wayback Machine, only other sources. Also, only waymore would let you know that there was a problem.

Installing

Clone this repo to your machine and then follow the instructions below, depending on whether you want install on a Chrome or Firefox browser:

Chrome

  1. Open the Extension Manager in Chrome by following: Kebab menu(three vertical dots) -> Extensions -> Manage Extensions

  2. If the developer mode is not turned on, turn it on by clicking the toggle in the top right corner.

  3. Now click on Load unpacked button on the top left

  4. Go the directory where you have Xnl Reveal folder and select it.

  5. The extension is now loaded. You can click on the extension icon in the toolbar, and then the pin icon to pin Xnl Reveal to your toolbar.

Firefox

IMPORTANT: With Firefox extensions, you will need to load it each time you open Firefox. Unfortunately I cannot add to the Firefox store to prevent this because it must be Manifest v3 to do that. Xnl Reveal has to use Manifest v2 (unless someone else can figure it out, because I couldn't) which has less security restrictions allowing it to work.

  1. Go to about:debugging in a new browser tab.

  2. Click on the This Firefox heading on the left of the page.

  3. Click the Load Temporary Add-on... button under the Temporary Extensions heading.

  4. Navigate to the Firefox folder from the downloaded repo and select any file, and then click Open.

  5. The extension is now loaded. You can click on the extension icon in the toolbar, then click the Settings cog icon, and select Pin to Toolbar.

Settings

Options Page

  • Chrome: If you right click the Xnl Reveal logo in the toolbar and select Options, you will be taken to the Options page.
  • Firefox: If you right click the Xnl Reveal logo in the toolbar and select Manage Extension, then click the Options tab to see the Options page.

You have the following options:

  • Canary token - When requests are made to test for reflection of query parameters, this is the value of the parameter that is used and checked for.
  • Check for reflection of ' " < - When requests are made to test for reflection of query parameters, the string '",xnl is appended to the end of the Canary token. If any of these characters reflect without being encoded, then this will also be reported. If passing those characters cause the Canary token not to be reflected at all (maybe a WAF blocks the <), then another request will be made just with the Canary token.
  • Show alert box for reflections - If this is selected, and Show query parameter reflections is selected on the Popup menu (see below) then a browser alert box will be displayed with details of any query parameters that reflect.
  • Copy reflection text to clipboard - If this is selected, and Show query parameter reflections is selected on the Popup menu (see below), when parameter reflections are found, the details are put in the users clipboard as-well as written to the DevTools Xnl Reveal tab (and on an alert box if requested). This means that as soon as you see an alert box or details in the DevTools tab, you can go to your notes and paste the details straight away. IMPORTANT: The browser may ask for the sites permission to interact with the clipboard. You need to accept this to use this functionality.
  • Param blacklist - This is a comma separated list of parameter names (e.g. param1,param2) that you do not want to replace with the canary token to check if it reflects. This can be used when testing certain parameters causes problems, e.g. logging you out.
  • Check delay - When a page is loaded, depending on settings, the extension will try to show hidden elements and enable disabled elements. However, sometimes parts of the page are loaded dynamically and they aren't in the original response. THe extension will try to show and enable again after this delay (in seconds) after the page has initially loaded.
Download Tool