A Burp Suite extension (Jython, classic IBurpExtender API) that generates XSS payloads for Intruder, based on the PortSwigger cheatsheet — with a unique marker, encoding variants, and support for loading a custom payload list.
- Random marker instead of a static
alert(1)— each attack generates a unique 6-character marker (e.g.alert(kqzmpv)), making it easier to identify hits and helping bypass simple filters that block literalalert(1). - Automatic encoding variants — every base payload is expanded into plain, URL-encoded, and HTML-entity-encoded versions (each variant can be toggled independently).
- Custom payload list loading — a button in the panel lets you pick a
.txtfile with payloads (one per line, may include the{MARK}placeholder), no code editing required. - Context-aware injection — optional appending of the payload to the original field value (
baseValue + payload) instead of always overwriting it. - Configuration panel inside Burp — a dedicated "XSS Gen" tab with checkboxes and the currently active list status.
- Logging to the Output tab — instead of
print()to the console.
- Burp Suite (Community or Professional)
- Jython standalone JAR configured in Burp (Extender → Options → Python Environment)
- Download Jython standalone and point Burp Suite to the
.jarfile:Extender → Options → Python Environment Location. - In Burp, go to
Extender → Extensions → Add. - Extension type:
Python. - Select the
BurpXSSPayloadGenerator.pyfile. - Click
Next— the Output console should show a successful load message.
- Send a request to Intruder and mark an attack position (
§...§). - In the
Payloadstab, select the payload type: Extension-generated. - Click
Select generator...and choose PortSwigger XSS Cheatsheet Payloads. - (Optional) Go to the XSS Gen tab in Burp's main bar to:
- enable/disable the random marker,
- enable/disable URL/HTML-encoded variants,
- load a custom payload list from a file,
- enable injection into the
baseValuecontext.
- Launch the attack.
A plain text file, one payload per line. The {MARK} placeholder is replaced with the current marker (random or 1, depending on settings):
<script>alert({MARK})</script>
<img src=x onerror=alert({MARK})>
"><svg onload=alert({MARK})>
The default list is grouped by injection context:
- HTML context (
<script>,<img>,<svg>,<iframe>) - attribute context (
" onfocus=... autofocus=") - JavaScript context (
;alert(...)//,'-alert(...)-') - HTML5 polyglot/bypass (
<details ontoggle=...>,<math><mtext>...)
- The extension relies on Burp's classic API (Jython) — it is not compatible with the Montoya API without adaptation.
- The base list is a starting point, not a complete WAF-bypass set — extend it via custom payload files tailored to your target.
- This tool is intended solely for use in authorized penetration testing activities. The user is responsible for ensuring usage complies with applicable law and the agreed testing scope.
MIT