Item logo image for HackBar

HackBar

Featured
4.2 (

54 ratings

)
Item media 1 (screenshot) for HackBar
Item media 2 (screenshot) for HackBar

Overview

A browser extension for Penetration Testing

## Contributor - 0140454 - GitHub: https://github.com/0140454 - lebr0nli - GitHub: https://github.com/lebr0nli - boylin0 - GitHub: https://github.com/boylin0 - HSwift - GitHub: https://github.com/HSwift ## How to open it? 1. Open "Developer tools" (Press F12 or Ctrl+Shift+I) 2. Switch to "HackBar" tab 3. Enjoy it ## Features * Load * From tab (default) * From cURL command * Supported * HTTP methods * GET * POST * application/x-www-form-urlencoded * multipart/form-data * application/json * Request editing mode * Basic * Raw * Custom payload * For more information, please visit https://github.com/0140454/hackbar/blob/master/README.md * Auto Test * Common paths (Wordlist from dirsearch included) * SQLi * Dump all database names (MySQL, PostgreSQL, MSSQL) * Dump tables from database (MySQL, PostgreSQL, MSSQL) * Dump columns from database (MySQL, PostgreSQL, MSSQL) * Union select statement (MySQL, PostgreSQL, MSSQL) * Error-based injection statement (MySQL, PostgreSQL, MSSQL) * Dump in one shot payload (MySQL) * Reference: https://github.com/swisskyrepo/PayloadsAllTheThings * Dump current query payload (MySQL) * Reference: https://github.com/swisskyrepo/PayloadsAllTheThings * Space to Inline comment * XSS * Vue.js XSS payloads * Angular.js XSS payloads for strict CSP * Some snippets for CTF * Html encode/decode with hex/dec/entity name * String.fromCharCode encode/decode * Helper function for converting payload with `atob` * LFI * PHP wrapper - Base64 * SSRF * AWS - IAM role name * SSTI * Jinja2 SSTI * Flask RCE Reference: https://twitter.com/realgam3/status/1184747565415358469 * Java SSTI * Shell * Python reverse shell cheatsheet * bash reverse shell cheatsheet * nc reverse shell cheatsheet * php reverse shell/web shell cheatsheet * Encoding * URL encode/decode * Base64 encode/decode * Hexadecimal encode/decode * Unicode encode/decode * Escape ASCII to hex/oct format * Hashing * MD5 * SHA1 * SHA256 * SHA384 * SHA512 ## Shortcuts * Load * Default: Alt + A * Split * Default: Alt + S * Execute * Default: Alt + X * Switch request editing mode * Default: Alt + M ## Third-party Libraries For more information, please visit https://github.com/0140454/hackbar#third-party-libraries

4.2 out of 5 54 ratings

Learn more about results and reviews.

Details

  • Version
    1.2.8
  • Updated
    December 30, 2024
  • Offered by
    0140454
  • Size
    1.72MiB
  • Languages
    English
  • Developer
    Email
    0140454@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

The developer has disclosed that it will not collect or use your data.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

Related

Pulsedive Threat Intelligence

5.0

Highlight IPs, domains, and URLs on any website to enrich them using Pulsedive's threat intelligence.

DotGit

4.8

An extension for checking if .git is exposed in visited websites

Sputnik

5.0

OSINT web extension

Vortimo OSINT-tool

4.2

OSINT Swiss army knife:bookmark/record pages, store screenshots, scrape and enrich entities. Finds text on every page + highlight.

Hack-Tools

4.6

The all in one Red team extension for web pentester

OWASP Penetration Testing Kit

4.8

OWASP Penetration Testing Kit

FindSomething

4.6

Find interesting things in the webpage's source code or JavaScript

X情报查询助手

4.3

鼠标上的情报专家。简化查询流程,提升分析效率。步刻科技有限公司出品

hackbar

5.0

A browser extension for using kbar in HackMD

d3coder

4.1

Encoding/Decoding Plugin for various types of encoding like base64, rot13 or unix timestamp conversion

Shodan

4.5

The Shodan plugin tells you where the website is hosted (country, city), who owns the IP and what other services/ ports are open.

Vulners Web Scanner

4.6

Tiny vulnerability scanner based on vulners.com vulnerability database. Passively scan websites while you surf internet!

Pulsedive Threat Intelligence

5.0

Highlight IPs, domains, and URLs on any website to enrich them using Pulsedive's threat intelligence.

DotGit

4.8

An extension for checking if .git is exposed in visited websites

Sputnik

5.0

OSINT web extension

Vortimo OSINT-tool

4.2

OSINT Swiss army knife:bookmark/record pages, store screenshots, scrape and enrich entities. Finds text on every page + highlight.

Hack-Tools

4.6

The all in one Red team extension for web pentester

OWASP Penetration Testing Kit

4.8

OWASP Penetration Testing Kit

FindSomething

4.6

Find interesting things in the webpage's source code or JavaScript

X情报查询助手

4.3

鼠标上的情报专家。简化查询流程,提升分析效率。步刻科技有限公司出品

Google apps
Create a Mobile Website
View Site in Mobile | Classic
Share by: