Hacker News new | ask | show | jobs
by outsidetheparty 2057 days ago
hitting mjt.xss.ht returns this:

/* THIS SUBDOMAIN HAS BEEN BANNED FROM THE XSS HUNTER SERVICE.

WE DO NOT ALLOW ABUSE OF OUR SERVICE, ALL SECURITY TESTING MUST BE AUTHORIZED.

Please use our contact form if you believe this ban was a mistake: https://xsshunter.com/contact */

1 comments

It previously returned an XSS test payload https://pbs.twimg.com/media/ElAYZTcX0AEyFUY?format=jpg&name=...
The character set used looks to be specifically authorized by law[1] so this doesn't appear to be unauthorized testing.

1. https://news.ycombinator.com/item?id=24921261

But not authorized by all the company register clone sites that would have triggered this. The service appears to be for testing your own site.