← Back to index

IAST Client HTTP Exfiltration Module

Exercises fetch/XHR/sendBeacon/image.src sinks with tainted data in URL, headers, or body.

Choose which source to prime before triggering sinks.

Taint is pulled from ?url=..., ?body=..., or the fields above when you click "Prime taint sources".