Surge.sh flies under the radar of many, but it’s pretty common among static-site developers. Personally, I find it to be the best place for hosting my XSS payloads. It’s free, easy, they provide SSL, and you can deploy scripts in (literally) seconds.
Earlier today I made a Tweet about how good Surge is for hosting XSS payloads, and a lot of people seemed to like it.
There were some comments that were asking about how to set it up, so I thought I’d write a blog about it.
- First you will need to install NodeJS, which you can download here: https://nodejs.org/en/
- Run the following command to install the surge CLI tool
npm install --global surge
That’s it, you’ve installed surge.
Deploying Your Payload
Create an empty directory and navigate to it.
mkdir mypayload cd mypayload
echo "alert(1)" > payload.js
Run “surge” to deploy all files in the current directory, which should just be payload.js if you have been following along.
The first time you run surge, it will ask for your email and a password. Once you’ve set that up it won’t ask you again.
The screenshot below shows the whole deployment process.
I should say that Surge isn’t just for XSS payloads, it is very good at hosting full static sites.
If you enjoyed this, follow me on my socials!