Take it like a gift
XSSer
Automatic framework to detect, exploit and report XSS vulnerabilities in web-based applications.
Collaborator Everywhere
Burp Suite extension which injects non-invasive headers to reveal backend systems.