DALFOX
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Fast, parameter-analysis-based XSS scanner by hahwul. Supports pipeline integration with other ProjectDiscovery tools.
INSTALLATION#
# Go install go install github.com/hahwul/dalfox/v2@latest # Homebrew brew install dalfox # Docker docker pull hahwul/dalfox # Snap sudo snap install dalfox # From source git clone https://github.com/hahwul/dalfox cd dalfox && go build
BASIC USAGE#
# Single URL dalfox url "https://example.com/search?q=test" # Multiple URLs from file dalfox file targets.txt # From stdin (pipeline) cat urls.txt | dalfox pipe # With specific parameter dalfox url "https://example.com/page" -p "search" dalfox url "https://example.com/page" -p "q,id,name"
SCANNING MODES#
# URL mode (single target) dalfox url "https://example.com/?q=test" # File mode (multiple targets) dalfox file urls.txt # Pipe mode (stdin) echo "https://example.com/?q=test" | dalfox pipe cat urls.txt | dalfox pipe # Server mode (API server) dalfox server -p 8090 # Then: curl "localhost:8090/scan?url=https://example.com/?q=test"
PAYLOAD OPTIONS#
# Custom payloads dalfox url URL --custom-payload payloads.txt # Blind XSS (with callback) dalfox url URL --blind "https://your.xss.ht" dalfox url URL -b "https://interact.sh/xxxx" # Custom alert value dalfox url URL --custom-alert-value "document.domain" dalfox url URL --custom-alert-type "str" # String alert dalfox url URL --custom-alert-type "none" # No alert # Remote payloads dalfox url URL --remote-payloads portswigger dalfox url URL --remote-payloads payloadbox # Trigger XSS with specific browser dalfox url URL --trigger # Open browser on finding
OUTPUT OPTIONS#
dalfox url URL -o results.txt # Plain text dalfox url URL -o results.json --format json # JSON dalfox url URL --found-action "notify.sh" # Execute on finding dalfox url URL --silence # Only output results dalfox url URL -v # Verbose
AUTHENTICATION & HEADERS#
# Custom headers
dalfox url URL -H "Authorization: Bearer TOKEN"
dalfox url URL -H "Cookie: session=abc123"
# Multiple headers
dalfox url URL -H "Authorization: Bearer TOKEN" -H "X-Custom: value"
# Cookie
dalfox url URL --cookie "session=abc123; token=xyz"
# HTTP method
dalfox url URL --method POST
dalfox url URL --method PUT
# POST data
dalfox url URL -d "param1=value1¶m2=value2"
dalfox url URL --data '{"key":"value"}' -H "Content-Type: application/json"
# User-Agent
dalfox url URL --user-agent "Mozilla/5.0"
PROXY & NETWORK#
# Proxy dalfox url URL --proxy http://127.0.0.1:8080 # Through Burp/Caido dalfox url URL --proxy socks5://127.0.0.1:9050 # Through Tor # Timeout dalfox url URL --timeout 10 # Delay between requests dalfox url URL --delay 500 # Milliseconds # Follow redirects dalfox url URL --follow-redirects
ADVANCED OPTIONS#
# WAF detection dalfox url URL --waf-evasion # Try WAF bypass # Mining (parameter discovery from response) dalfox url URL --mining-dict # Dictionary-based dalfox url URL --mining-dom # DOM-based dalfox url URL --mining-dict --mining-dom # Both # Only DOM XSS dalfox url URL --only-discovery dalfox url URL --skip-bav # Skip BAV analysis # Grep for specific patterns dalfox url URL --grep "error|exception|warning" # Only specific XSS type dalfox url URL --only-custom-payload # Only custom payloads # Skip specific checks dalfox url URL --skip-mining-dict dalfox url URL --skip-mining-dom dalfox url URL --skip-xss-scanning
PIPELINE INTEGRATION#
# ProjectDiscovery pipeline subfinder -d example.com | httpx | katana -jc | dalfox pipe # With parameter discovery cat urls.txt | gau | dalfox pipe # Arjun → Dalfox arjun -u https://example.com/page --stable -o params.json # Parse Arjun output and feed to Dalfox # With wayback URLs echo example.com | waybackurls | dalfox pipe # With Nuclei (complementary) nuclei -l targets.txt -tags xss # Template-based cat targets.txt | dalfox pipe # Parameter-based
COMMON WORKFLOWS#
# 1. Quick XSS scan on a URL with parameters
dalfox url "https://target.com/search?q=test&page=1"
# 2. Blind XSS hunting
dalfox url URL -b "https://your.interact.sh/callback"
# 3. Bug bounty pipeline
subfinder -d target.com | httpx | katana -jc | \
grep "=" | dalfox pipe -b "https://your.xss.ht" -o results.txt
# 4. Authenticated scan
dalfox url URL -H "Cookie: session=TOKEN" -H "Authorization: Bearer JWT"
# 5. Through proxy for manual review
dalfox url URL --proxy http://127.0.0.1:8080
TIPS#
- Parameter analysis is Dalfox's strength (auto-detects reflections) - Use --blind for stored/blind XSS with callback server - Mining mode discovers hidden parameters from page content - Pipeline mode (pipe) is ideal for large-scale scanning - Set --delay to avoid rate limiting on bug bounty targets - Route through proxy (--proxy) to review findings in Burp/Caido - Combine with katana (crawler) for comprehensive coverage - --waf-evasion helps against WAF-protected targets - Custom payloads for specific frameworks (React, Angular, etc.) - Server mode allows building XSS scanning into automation