HackBar
Featured

HackBar

A browser extension for penetration testing with SQLi, XSS, LFI, SSRF, SSTI, encoding, hashing, and request

★★★★☆ 4.2 55 reviews 80K+ users · Developer Tools
Runs on all sites

What it does

Permissions and access

Taken from the extension's own manifest file inside the package. The store listing does not spell this out, so it is worth reading before you install.

Can act on Every website you visit
PermissionWhat it allows
declarativeNetRequestBlock or modify network requests
scriptingRun its own code on pages
storageStore its own settings and data
webRequestWatch your network requests

Requests 4 permissions — extensions doing the same job average 3.9.

Technical details

Version1.2.8
Download size1.7 MB
PlatformManifest V3
Needs Chrome107+
InterfaceDevTools tab
Keyboard shortcuts4
Interface languages Not translated

Keyboard shortcuts

ShortcutAction
Alt+ATrigger 'Load'
Alt+STrigger 'Split'
Alt+XTrigger 'Execute'
Alt+MSwitch between 'Basic' and 'Raw' mode

Description

HackBar is a powerful browser extension designed for penetration testers and security researchers. It integrates directly into the browser's Developer Tools, providing a convenient panel where users can craft, modify, and execute HTTP requests with a wide range of payloads and encoding options. This tool streamlines the process of testing web applications for vulnerabilities, making it an essential addition to any security professional's toolkit.

Key Features

  • Request Loading: Easily load requests from the current browser tab or from a cURL command. This allows testers to quickly capture an existing request and modify it for further testing, saving time and reducing errors.
  • HTTP Method Support: Supports GET and POST methods with various content types including application/x-www-form-urlencoded, multipart/form-data, and application/json. This flexibility ensures compatibility with a wide range of web forms and APIs.
  • Request Editing Modes: Choose between Basic and Raw editing modes. Basic mode provides a user-friendly interface for modifying parameters, while Raw mode allows direct manipulation of the raw HTTP request for advanced users.
  • Custom Payloads: Users can define and use custom payloads to test for specific vulnerabilities or to automate repetitive tasks. This feature is particularly useful for security assessments that require tailored input.
  • Auto Test: Automatically test common paths on the target server using a built-in wordlist from dirsearch. This helps identify hidden directories or files that may be vulnerable.
  • SQL Injection (SQLi) Tools: Generate and execute SQL injection payloads for MySQL, PostgreSQL, and MSSQL. Features include dumping database names, tables, columns, union select statements, error-based injection, and one-shot payloads for MySQL. This assists in identifying and exploiting SQL injection vulnerabilities.
  • XSS Payloads: Includes a collection of Vue.js and Angular.js XSS payloads, as well as snippets for CTF challenges. Also provides encoding/decoding utilities for HTML (hex, decimal, entity name) and JavaScript (String.fromCharCode), and a helper to convert payloads using atob.
  • LFI (Local File Inclusion): Generate PHP wrapper payloads for Base64 encoding to test for LFI vulnerabilities.
  • SSRF (Server-Side Request Forgery): Includes payloads to enumerate AWS IAM role names, aiding in SSRF testing.
  • SSTI (Server-Side Template Injection): Provides Jinja2 (including Flask RCE reference) and Java SSTI payloads to test for template injection vulnerabilities.
  • Reverse Shell Cheatsheets: Quick access to Python, bash, nc, and PHP reverse shell commands, facilitating post-exploitation tasks.
  • Encoding Tools: URL encode/decode, Base64 encode/decode, hexadecimal encode/decode, Unicode encode/decode, and escape ASCII to hex/oct format. These tools are essential for obfuscating payloads or decoding data.
  • Hashing Tools: Generate MD5, SHA1, SHA256, SHA384, and SHA512 hashes directly within the extension, useful for password cracking or data integrity checks.
  • Keyboard Shortcuts: Speed up workflows with shortcuts: Alt+A to load request, Alt+S to split, Alt+X to execute, and Alt+M to switch between editing modes.

HackBar is an open-source project with contributions from multiple developers, and its full documentation and third-party library details are available on the official GitHub repository. Whether you are performing a penetration test, participating in a CTF, or simply exploring web security, HackBar provides the essential tools in a single, accessible interface.

Extensions that do the same job

Matched by what these extensions actually do, not by store category, and sorted so the ones asking for the least access come first.

ExtensionSite accessPermissionsUsersRating
HackBar — this page All sites 4 80K 4.2★
Figma Limited 4 200K 4.2★
GitZip for github Limited 2 100K 4.1★
IP Address and Domain Information Limited 1 100K 4.4★
Lightning Studio Limited 3 100K 3.9★
Pixel Measurement Limited 3 100K 4.5★
AI Code Finder, Alerts, Ask Questions about Papers: CatalyzeX Limited 3 50K 4.8★

Want the same thing with less access? Figma, GitZip for github, IP Address and Domain Information ask for fewer permissions than this one.

Store data last checked August 16, 2026.