Fransyfox ავტორი 0xmoose
Fransyfox — postMessage transceiver for security researchers. Intercept, track, analyze, splice, and replay cross-frame postMessage traffic.
იმუშავებს Firefox Android™იმუშავებს Firefox Android™
წააკითხეთ QR-კოდი ამ გაფართოების გასახსნელად Firefox-ში Android-ზე
გაფართოების მონაცემები
ეკრანის სურათები
გაფართოების შესახებ
Fransyfox watches postMessage traffic on every web page you visit. It detects postMessage listeners registered across all frames and origins, shows their source code and stack traces, captures cross-frame messages, and lets you filter, splice, and replay them.
Built for bug bounty hunters and client-side security researchers.
Features:
• Listener detection — monitors every postMessage listener registered via addEventListener/onmessage across all frames. Shows source code, stack traces, and frame hops. Unwraps wrappers (jQuery, Sentry, Raven, NewRelic, Rollbar, Bugsnag, Zone.js, Vue, React, and more).
• Message interception — captures window and MessagePort traffic with origin, source/target frame, payload, and timing.
• Findings engine — rule-based analysis flags risky listeners (innerHTML, eval, location.href, missing origin checks, etc.) ranked by severity.
• Match & Replace — live regex splicing of postMessage payloads in both directions. Intercept and rewrite messages as they fly.
• Composer — craft and send your own postMessage payloads into any frame.
• Map / Timeline — frame-tree graph and message timeline views.
• Filtering & blocking — block noisy or trusted listeners by code, URL, or regex.
• Deduplication — identical listeners from the same source are collapsed.
• Syntax highlighting & prettify — highlight.js with custom color rules and code beautify.
• Import/export — blocked lists, listeners, messages, and findings as JSON.
• External logging — forward detected listeners to your own endpoint.
Named in honor of Frans Rosén and his original postMessage-tracker. Spiritual successor to postMessage-tracker → FancyTracker → FransyTracker → Fransyfox.
Source code: https://github.com/GangGreenTemperTatum/Fransyfox
License: MIT
Built for bug bounty hunters and client-side security researchers.
Features:
• Listener detection — monitors every postMessage listener registered via addEventListener/onmessage across all frames. Shows source code, stack traces, and frame hops. Unwraps wrappers (jQuery, Sentry, Raven, NewRelic, Rollbar, Bugsnag, Zone.js, Vue, React, and more).
• Message interception — captures window and MessagePort traffic with origin, source/target frame, payload, and timing.
• Findings engine — rule-based analysis flags risky listeners (innerHTML, eval, location.href, missing origin checks, etc.) ranked by severity.
• Match & Replace — live regex splicing of postMessage payloads in both directions. Intercept and rewrite messages as they fly.
• Composer — craft and send your own postMessage payloads into any frame.
• Map / Timeline — frame-tree graph and message timeline views.
• Filtering & blocking — block noisy or trusted listeners by code, URL, or regex.
• Deduplication — identical listeners from the same source are collapsed.
• Syntax highlighting & prettify — highlight.js with custom color rules and code beautify.
• Import/export — blocked lists, listeners, messages, and findings as JSON.
• External logging — forward detected listeners to your own endpoint.
Named in honor of Frans Rosén and his original postMessage-tracker. Spiritual successor to postMessage-tracker → FancyTracker → FransyTracker → Fransyfox.
Source code: https://github.com/GangGreenTemperTatum/Fransyfox
License: MIT
0 შეფასება 0 მიმომხილველისგან
ნებართვები და მონაცემები
მოთხოვნილი ნებართვები:
- შემმუშავებლის ხელსაწყოების გამოყენება, გახსნილ ჩანართებზე თქვენს მონაცემებთან წვდომისთვის
- ბრაუზერის ჩანართებთან წვდომა
- გვერდებზე გადაადგილებისას ბრაუზერის მოქმედებებთან წვდომა
დამატებითი ნებართვები:
- თქვენს მონაცემებთან წვდომა ყველა საიტზე
აღსარიცხი მონაცემები:
- შემქმნელის თქმით ეს გაფართოება არ საჭიროებს მონაცემთა აღრიცხვას.
დამატებითი მონაცემები
- დამატების ბმულები
- ვერსია
- 0.2.0
- ზომა
- 2,2 მბ
- ბოლო განახლება
- 24 დღის წინ (7 სექ 2026)
- მსგავსი კატეგორიები
- ლიცენზია
- MIT-ლიცენზია
- ვერსიის ისტორია
- კრებულში დამატება