-
Notifications
You must be signed in to change notification settings - Fork 0
Fire Range
CommonHuman-Lab edited this page May 22, 2026
·
2 revisions
The StingXSS Fire Range is a deliberately vulnerable Flask app that ships with OctoRig. It provides injectable endpoints that the scanner is verified against on every change.
# Start Fire Range (OctoRig required)
./octorig.sh start StingXSSstingxss -u "http://127.0.0.1:17477" --crawl --max-pages 100 --level 2 --report-html report.htmlThe Fire Range covers reflected, DOM, stored, CRLF, and header-injection endpoints — enough to exercise the full scanner surface.