
A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements and enable disabled elements.
This is a Chrome/Firefox Extension that can do the following:
'," and < are reflected without being encoded.Xnl Reveal tab.Xnl Reveal tab).The ability to show an alert for reflected parameters was inspired by a comment by @renniepak on Episode 42 of the Critical Thinking - Bug Bounty Podcast where he mentioned he had his own browser extension that let him know about any reflections.
The number of reflected parameters found is shown by a green badge on the extension icon. However, if any of the reflected parameter names are in a categories described in the "sus" parameters research by @Jhaddix and @G0LDEN_infosec then the badge will be red. If there are any "sus" parameters, then the categories will also be shown in the output to the DevTools Xnl Reveal tab, alert box and clipboard, e.g. boringParameter, query [XSS], path [LFI/RFI | SSRF | XSS] (this is the same as the "sus" parameters identification in my GAP Burp Extension).
The ability to show hidden elements, and enable disabled elements, was inspired by this Tweet by Critical Thinking - Bug Bounty Podcast and I initially created as browser bookmarks.
The extension icon is normally shown with a black background
, but if the icon appears with a red background
, then it indicates that the Wayback CDX Server API is probably unavailable. Even if the main features are disabled, the extension will check the status of the API every 10 minutes.
IMPORTANT: When using tools like waymore, waybackurls or gau to get URLs from the Wayback archive, it uses the CDX Server API. If the API is down, you will not be getting any data from the Wayback Machine, only other sources. Also, only waymore would let you know that there was a problem.
Clone this repo to your machine and then follow the instructions below, depending on whether you want install on a Chrome or Firefox browser:
Open the Extension Manager in Chrome by following: Kebab menu(three vertical dots) -> Extensions -> Manage Extensions
If the developer mode is not turned on, turn it on by clicking the toggle in the top right corner.
Now click on Load unpacked button on the top left
Go the directory where you have Xnl Reveal folder and select it.
The extension is now loaded. You can click on the extension icon in the toolbar, and then the pin icon to pin Xnl Reveal to your toolbar.
IMPORTANT: With Firefox extensions, you will need to load it each time you open Firefox. Unfortunately I cannot add to the Firefox store to prevent this because it must be Manifest v3 to do that. Xnl Reveal has to use Manifest v2 (unless someone else can figure it out, because I couldn't) which has less security restrictions allowing it to work.
Go to about:debugging in a new browser tab.
Click on the This Firefox heading on the left of the page.
Click the Load Temporary Add-on... button under the Temporary Extensions heading.
Navigate to the Firefox folder from the downloaded repo and select any file, and then click Open.
The extension is now loaded. You can click on the extension icon in the toolbar, then click the Settings cog icon, and select Pin to Toolbar.
Xnl Reveal logo in the toolbar and select Options, you will be taken to the Options page.Xnl Reveal logo in the toolbar and select Manage Extension, then click the Options tab to see the Options page.
You have the following options:
Canary token - When requests are made to test for reflection of query parameters, this is the value of the parameter that is used and checked for.Check for reflection of ' " < - When requests are made to test for reflection of query parameters, the string '",xnl is appended to the end of the Canary token. If any of these characters reflect without being encoded, then this will also be reported. If passing those characters cause the Canary token not to be reflected at all (maybe a WAF blocks the <), then another request will be made just with the Canary token.Show alert box for reflections - If this is selected, and Show query parameter reflections is selected on the Popup menu (see below) then a browser alert box will be displayed with details of any query parameters that reflect.Copy reflection text to clipboard - If this is selected, and Show query parameter reflections is selected on the Popup menu (see below), when parameter reflections are found, the details are put in the users clipboard as-well as written to the DevTools Xnl Reveal tab (and on an alert box if requested). This means that as soon as you see an alert box or details in the DevTools tab, you can go to your notes and paste the details straight away. IMPORTANT: The browser may ask for the sites permission to interact with the clipboard. You need to accept this to use this functionality.Param blacklist - This is a comma separated list of parameter names (e.g. param1,param2) that you do not want to replace with the canary token to check if it reflects. This can be used when testing certain parameters causes problems, e.g. logging you out.Check delay - When a page is loaded, depending on settings, the extension will try to show hidden elements and enable disabled elements. However, sometimes parts of the page are loaded dynamically and they aren't in the original response. THe extension will try to show and enable again after this delay (in seconds) after the page has initially loaded.