Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/yuyudhn/blindxss-lite
Phishing ToolsPayload GenerationWeb Application ExploitationData ExfiltrationInformation GatheringWeb SecurityPenetration TestingCommand and ControlUtilities & FrameworksRed Teaming
GitHub
11029 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
yuyudhn/blindxss-lite

blindxss-lite

A lightweight Blind XSS (Cross-Site Scripting) collector and payload server built with Flask

View Repository

blindxss-lite

A lightweight Blind XSS (Cross-Site Scripting) collector and payload server built with Flask. It serves a JavaScript payload that captures victim browser data (cookies, localStorage, DOM snippets, etc.) and forwards it to a SQLite-backed dashboard protected by HTTP Basic Auth.

Features

  • Payload delivery — /p.js serves a self-contained JS payload using sendBeacon or fetch
  • Collector endpoints — POST /c (JSON/FormData) and GET /c.gif (CSP-friendly pixel beacon)
  • Admin dashboard — /events lists captured events, /events/<id>/view shows full details
  • Payload generator — /payloads offers 14 XSS payload variants plus a custom JS editor
  • HTTP Basic Auth — admin routes protected by ADMIN_USER / ADMIN_PASSWORD
  • SQLite persistence — database auto-created on first run; deleting bxss.db rebuilds it fresh
  • Docker-ready — Dockerfile and docker-compose.yml included
  • Rate limiting — SQLite-backed sliding-window limiter for collector endpoints (shared across workers)

Quick Start

Docker Compose

# Set credentials
echo "ADMIN_USER=admin" > .env
echo "ADMIN_PASSWORD=your-admin-password" >> .env

# Build and run
docker compose up -d --build

Dashboard: http://127.0.0.1:8089/events (browser will prompt for Basic Auth)

Without Docker

pip install -r requirements.txt
export ADMIN_USER="admin"
export ADMIN_PASSWORD="your-admin-password"
gunicorn -b 127.0.0.1:8080 --workers 2 --threads 4 wsgi:app

Usage

  1. Visit /payloads (after authenticating) to copy an XSS payload.
  2. Inject the payload into a target input field suspected of Blind XSS.
  3. When a victim loads the page, the payload runs and sends their data to your server.
  4. View captured events at /events.

Endpoints

Collector (public, no auth)

MethodPathDescription
GET/p.jsXSS payload JavaScript
POST/cReceives JSON/FormData from payload
GET/c.gifPixel beacon (CSP-friendly)

Admin (HTTP Basic Auth)

MethodPathDescription
GET/eventsLast 500 events
GET/events/<id>Event detail as JSON
GET/events/<id>/viewEvent detail as HTML
GET/POST/payloadsPayload generator + custom JS editor

Utility

MethodPathDescription
GET/_healthzHealth check

Configuration

VariableDefaultDescription
ADMIN_USERadminDashboard username
ADMIN_PASSWORDchangemeDashboard password
DB_PATH./bxss.dbSQLite database path
MAX_BODY524288Max collector body size (bytes)
RATE_LIMIT_COUNT60Max collector requests per window (per IP)
RATE_LIMIT_WINDOW60Rate limit window in seconds
LOG_LEVELINFOPython logging level

Custom JS is edited and stored via the /payloads admin page (persisted in the SQLite settings table) and appended to /p.js. It is no longer read from a file.

Project Structure

blindxss-lite/
├── wsgi.py              # WSGI entry point
├── requirements.txt     # Python dependencies
├── Dockerfile           # Container image
├── docker-compose.yml   # Compose config
├── .env                 # Credentials (don't commit)
└── app/
    ├── __init__.py      # App factory, CORS, health check
    ├── config.py        # Config + .env loader
    ├── db.py            # SQLite layer
    ├── collectors.py    # /p.js, /c, /c.gif
    ├── events.py        # /events admin
    ├── payloads.py      # /payloads admin
    ├── utils.py         # Helpers + Basic Auth decorator
    ├── static/
    │   └── style.css
    └── templates/
        ├── events.html
        ├── event.html
        └── payloads.html

Payload Data Collected

  • Document title and URL
  • Origin and referrer
  • document.cookie
  • User agent
  • localStorage and sessionStorage (all keys)
  • DOM snippet (first 200KB, zlib+base64 compressed)

Showcase

Payloads: Payload Page

Result:

Result detail:

Security Notes

  • Admin routes require HTTP Basic Auth. Use a strong password in production.
  • Collector endpoints are intentionally unauthenticated.
  • All origins are allowed for CORS so payloads can send data from any site.
  • SQLite-backed rate limiting helps mitigate collector abuse and is shared across workers.
  • .env should never be committed to version control.
Download Tool