How To Find Cross Site Scripting Xss
How To Find Cross Site Scripting Xss
Stored/persistent XSS
Reflected/non-persistent XSS
DOM-Based/client-Side XSS
self-XSS
See how the server rsponds, try to bypass the restrictions such as tag
removal, encoding or character
Burp suit
PwnXSS
Xspear
XSSStrike
Google Dorks
Google dorking is one of the easy way to find websites containing XSS
If you see a vulnerable parameter in the url open it and start looking for
any XSS
Here you will get you more hidden endpoints that you may not find when
Google Dorking
https://google. com/api/*