Simple Hash XSS

A Chrome Extension that automates testing of a simple hash XSS payload commonly triggered by ad code, optionally collecting the results for research purposes.

Usage

Install the extension from here. Be sure to browse without AdBlock for best results.

Known Issues

This will likely break sites that use hash parameters extensively, for example Gmail.