XSS Discovery
- automated tools for XSS discovery are XSS Strike, Brute XSS, and XSSer.
- can also use Burp Suite pro
Manual Discovery
- finding advanced XSS vulnerabilities requires advanced code review skills.
- basic method - manually test a lot of payloads from PayloadAllTheThings or PayloadBox.
