--- name: hunt-html-injection description: Hunt HTML Injection category: security risk: offensive source: https://github.com/elementalsouls/Claude-BugHunter source_repo: elementalsouls/Claude-BugHunter source_type: community date_added: '2026-09-20' license: MIT license_source: https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE compatibility: Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled. sources: hackerone_public, public_research report_count: 6 --- > **⚠️ AUTHORIZED USE ONLY** > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Misuse of this tool is illegal and strictly prohibited. > **Mandatory confirmation gate** > Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target: > 1. Ask the user to state the exact target URL, IP, account, or resource. > 2. Ask the user to confirm written authorization and the permitted scope. > 3. Show the exact command(s) and explain their expected effect. > 4. Wait for explicit confirmation in the current conversation. > > Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab. ## What is HTML Injection HTML Injection occurs when user input is inserted into a page's HTML without escaping, so injected tags are rendered by the browser as markup rather than displayed as literal text. Unlike XSS, the injected content does not require JavaScript execution — injecting ``, `

`, ``, ``, or `
` tags is sufficient. **To PROVE impact unambiguously, escalate to an active vector carrying a unique numeric canary** — e.g. `">` or ``. A distinctive 4+ digit number (not `alert(1)`) distinguishes YOUR reflected injection from the example payloads practice pages embed in their own hint text. Proof = the raw, unescaped vector with your canary appears in the response. **Impact:** - Phishing via injected `
` or `` tags - UI defacement — `

HACKED

` renders visually on the page - Credential harvesting via injected login forms - Redirect via `` - Stepping stone to XSS (may be blocked by WAF on `` — the same unsanitised input may allow full XSS. ## Proof Confirmed when your injected tag appears in the response body with literal `<` angle brackets (not HTML-encoded). A safe app renders `<b>CANARY</b>`; a vulnerable app renders `CANARY`. ## Distinguishing HTML Injection from XSS - HTML injection: `text` renders as **text** in the browser — no JS execution needed. - XSS: `` executes JavaScript. Some WAFs block `