TriviaSecurity XSS Security Playground
Form One -- No security. Everything goes.
Form Two -- Personalized CSS. no html symbols allowed.
Form Three -- Html escaped. Image,avatar,etc url form.
Form Four -- Nothing is escaped.. but some keywords are stripped.
Form Five -- Poor addslashes security.
Amado XSS Kit
Generates a url from a number of variables. Only supports GET variable manipulation.
Current encoding/obfuscation features:
Javascript:: String.fromCharCode(..)
FULL Hex URL Encode for Obfuscation