Default Payloads Seeds

seed data

Default payloads that come with xodbox.


Default Header

Adds the default header to all HTTP responses.

Redirect

HTTP Redirects

Remote Address Reflector

A restrictive robots.txt

Robots TXT

A restrictive robots.txt

Build MDaaS

Build random binaries

Inspect

Reflect back HTTP requests in various formats

XSS HTML

Returns HTML that embeds xss-js

XSS JavaScript

Returns JS that embeds an image back to xodbox

Default Favicon

Redirects to the default logo.

Bash Reverse Shell

BusyBox Reverse Shell

Bind Shell

Requires bind-shell in static dir

BusyBox Reverse Shell

BusyBox Reverse Shell

Detect platform

detect platform

HTML IFrame With Request Params

Returns an HTML page with an iframe src to f query parameter

Open Graph

Embed request params in open graph elements.

Python Reverse Shell

Python Reverse Shell

Reverse Shell

Requires bind-shell in static dir

Simple SSH

Simple SSH (requires build of simple ssh server in static dir)

Simple SSH Service

Simple SSH Service (requires build of simple ssh server in static dir)

XSS Image Template

A text template for quickly embedding js execution hooks into pages the image tags

XXE Callback

More XXE

XXE DTD

More XXE

XXE SVG Hostname

Returns an SVG payload with XXE to get files

XXE SVG Passwd

Returns an SVG payload with XXE to get files

XXE SVG Request Params

Returns an SVG payload with XXE to get files

XXE System

More XXE

Default Page

returns a simple page if nothing is matched

In Development Seeds

These seeds are not ready for production and may never be.

Last modified November 28, 2025: pin actions (5230c1e)