
快速XSS扫描器,具备参数分析、WAF指纹识别和DOM/AST验证功能。支持通过CLI、管道或REST API进行反射型、存储型和基于DOM的XSS检测。
Dalfox 是一款功能强大的开源工具,专注于自动化,非常适合快速扫描 XSS 漏洞和分析参数。其先进的测试引擎和特色功能旨在简化检测和验证漏洞的过程。
scan(URL / 文件 / 管道 / 原始 HTTP,自动检测)、server、payload、mcp--waf-min-confidence以及测试所需的各种选项 :D
brew install dalfox
# https://formulae.brew.sh/formula/dalfox
sudo snap install dalfox
yay -S dalfox
# or
paru -S dalfox
有关手动构建说明,请参阅安装指南。
Nix 或 NixOS 用户可以使用该软件包。请注意,最新版本可能仅存在于 unstable 频道中。
nix-shell -p dalfox
对于启用了 flakes 的 Nix 用户:
# Run directly
nix run github:hahwul/dalfox -- scan https://example.com
# Install
nix profile install github:hahwul/dalfox
# Development environment for hacking on Dalfox itself
git clone https://github.com/hahwul/dalfox && cd dalfox && nix develop
该 flake 还暴露了 overlays.default,因此 NixOS 和 home-manager 用户可以基于自己的 nixpkgs 构建 Dalfox。有关该模块片段及其他详细信息,请参阅安装指南。
预构建的二进制文件(包括适用于 Linux 的静态链接 musl 变体)可在 GitHub Releases 页面获取。
dalfox [mode] [target] [flags]
dalfox scan http://example.com -b https://callbackdalfox scan urls.txt --custom-payload mypayloads.txtcat urls.txt | dalfox scan --headers "AuthToken: xxx"dalfox scan 'https://example.com/?q=FUZZ&page=1' --inject-marker FUZZdalfox scan https://example.com -H 'X-Search: FUZZ' --inject-marker FUZZ正在寻找 Go (v2.x) 版本?Dalfox v3 是用 Rust 完全重写的版本。Go 代码库保留在 v2 分支上,并继续接收安全回溯补丁。有关支持政策,请参阅 SECURITY.md,有关 v3 中的变更,请参阅迁移指南。
如果您想为该项目做出贡献,请参阅 CONTRIBUTING.md 并提交您精彩的 Pull-Request。
该名称来自 'Dal'(달)🌙,韩语中“月亮”的意思,结合 'Fox' 🦊。
