Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

License

NotificationsYou must be signed in to change notification settings

hahwul/dalfox

Repository files navigation


dalfox

Dalfox is a powerful open-source tool that focuses on automation, making it ideal for quickly scanning for XSS flaws and analyzing parameters. Its advanced testing engine and niche features are designed to streamline the process of detecting and verifying vulnerabilities.

Key features

  • Modes:URL,SXSS,Pipe,File,Server,Payload
  • Discovery: Parameter analysis, static analysis, BAV testing, parameter mining
  • XSS Scanning: Reflected, Stored, DOM-based, with optimization and DOM/headless verification
  • HTTP Options: Custom headers, cookies, methods, proxy, and more
  • Output: JSON/Plain formats, silence mode, detailed reports
  • Extensibility: REST API, custom payloads, remote wordlists

And the various options required for the testing :D

Installation

Homebrew (macOS/Linux)

brew install dalfox# https://formulae.brew.sh/formula/dalfox

Snapcraft (Ubuntu)

sudo snap install dalfox

Nixpkgs (NixOS)

A package is available for Nix or NixOS users. Keep in mind that the latest releases might onlybe present in theunstable channel.

nix-shell -p dalfox

From Source

go install github.com/hahwul/dalfox/v2@latest

SeeInstallation guide for details.

Usage

dalfox [mode] [target] [flags]
  • Single URL:dalfox url http://example.com -b https://callback
  • File Mode:dalfox file urls.txt --custom-payload mypayloads.txt
  • Pipeline:cat urls.txt | dalfox pipe -H "AuthToken: xxx"

Check theUsage andRunning documents for more examples.

Contributing

if you want to contribute to this project, please seeCONTRIBUTING.md and Pull-Request with cool your contents.

About the Name

As for the name, Dal() is the Korean word for "moon," while "Fox" stands for "Finder Of XSS" or 🦊

About

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

Topics

Resources

License

Code of conduct

Security policy

Stars

Watchers

Forks

Sponsor this project

 

Packages

 
 
 

Contributors35

Languages


[8]ページ先頭

©2009-2025 Movatter.jp