dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

MIT License

Stars
3.7K
Committers
27
dalfox - v2.2.8

Published by hahwul almost 4 years ago

Changelog

f0c4187 remove armv7 / snapcraft issue
a78c455 release 2.2.8
cf8a505 (#163) Fixed bugs in server mode

dalfox - v2.2.7

Published by hahwul almost 4 years ago

dalfox - v2.2.6

Published by hahwul almost 4 years ago

Changelog

bc76ad4 update
f0ed663 chore: update contributors [skip ci]
f770140 chore: update contributors [skip ci]
8e2630d chore: update contributors [skip ci]
1221845 chore(deps): update module swaggo/swag to v1.7.0
8abf5ce chore(deps): update module swaggo/echo-swagger to v1.1.0
0222f6e chore(deps): update module logrusorgru/aurora to v3
967fdda chore(deps): update module briandowns/spinner to v1.12.0
b10c859 add wiki on jekyll
a5ff34c Update usage.md
67a1db2 Update oneliner.md
88654c5 Update codeql-analysis.yml
2203312 Update codeql-analysis.yml
44ef0fc Update and rename main.yml to contributors.yml
2bb9207 Update README.md
2d4c6c3 Update README.md
5df400d Update README.md
0fc2791 Update README.md
e0483c7 Update README.md
cfb3995 Update README.md
1a8e267 Release v2.2.6
94038fc Merge pull request #156 from dwisiswant0/patch-1
c0a4606 Merge pull request #155 from hahwul/renovate/github.com-swaggo-echo-swagger-1.x
52598fa Merge pull request #154 from hahwul/renovate/github.com-swaggo-swag-1.x
4e8a1f9 Merge pull request #152 from hahwul/renovate/github.com-briandowns-spinner-1.x
6c4aa2e Merge pull request #151 from hahwul/renovate/github.com-logrusorgru-aurora-3.x
5d8c9eb Create main.yml
a0c07b6 Create codeql-analysis.yml
2fc0fdd Create CNAME
f5d9620 Change readme and docs
6025e78 Add inJS paylaod pattern
d2e03fb Add inJS paylaod pattern
41605b4 ✏️ Fix typo
6baa89b (#157) Add --debug option and change default logging

dalfox - v2.2.5

Published by hahwul almost 4 years ago

Changelog

b6cc4dc release v2.2.5
b13c254 Supported ARMv6/ARMv7/ARM64 in linux/freebsd
30c0821 (Closed #149) Updated Event handler and Gf-Patterns
fc921e1 (Closed #148) Updated Gf-Patterns

dalfox - v2.2.4

Published by hahwul almost 4 years ago

Changelog

91d1d46 wip
8fd67fb update scan.go
2fbba98 support for FoundAction BAV
c6ce088 release v2.2.4
68fd80b delete gitignore
e6b155e Update question.md
4844498 Update bug_report.md
0e73683 Merge remote-tracking branch 'upstream/master'
c4020a5 Merge pull request #144 from bp0lr/bavFoundAction
e502f1a Improve code quality with gofmt
85f2dd2 Improve code quality / misspell
83efaee Improve code quality / misspell
7844765 Improve code quality / Codacy
8bcd04c Add .gitignore

dalfox - v2.2.3

Published by hahwul almost 4 years ago

Changelog

e894800 release v2.2.3
3d9f9c6 Update README.md
5832411 (Fixed #143) Custom payloads and blind xss are also tested for mining parameters
6d2964b (#142) Remove basic/beare regex pattern

dalfox - v2.2.2

Published by hahwul almost 4 years ago

Changelog

2502122 release v2.2.2
3dae0c6 (Fixed #139, #140) Added --only-custom-payload / --skip-grepping flags
eaa2d84 (Fixed #139, #140) Added --only-custom-payload / --skip-grepping flags
8f91476 (Closed #138) Remove google-captcha/secret-key/access-key in built-in grepping pattern

dalfox - v2.2.1

Published by hahwul almost 4 years ago

Changelog

b807fe7 release v2.2.1
e38d41a Update module swaggo/swag to v1.6.9
03fac85 Update module swaggo/swag to v1.6.8
1682cb7 Update module spf13/cobra to v1.1.1
3813744 Update module spf13/cobra to v1.1.0
c7a8a9d Update module PuerkitoBio/goquery to v1.6.0
5950983 Update actions/setup-go action to v2
54991a0 Merge pull request #133 from hahwul/renovate/actions-setup-go-2.x
0f390c4 Merge pull request #132 from hahwul/renovate/github.com-swaggo-swag-1.x
023f7cc Merge pull request #131 from hahwul/renovate/github.com-spf13-cobra-1.x
a9b8b32 Merge pull request #129 from hahwul/renovate/github.com-swaggo-swag-1.x
ef44705 Merge pull request #128 from hahwul/renovate/github.com-spf13-cobra-1.x
ba1824c Merge pull request #127 from hahwul/renovate/github.com-puerkitobio-goquery-1.x
a25b932 Add multi-stage build in dockerfile
85cb3ab Add home plug for home permission / #134
896f9cc (#137) downgrade require go version

dalfox - v2.2.0

Published by hahwul about 4 years ago

Changelog

3a54ac6 update log
51d199e update docker tag to golang:1.15.2-alpine3.12
bde83c0 sqli code clean up
1b0ef78 sqli basic support
c86f287 fixed gofmt
1fe0cd5 fixed double encoding bug on optimization.
3bb8f96 fix codacy warning 2
61dad27 fix codacy warning
d83920c fix bug on MakeRequestQuery
4339226 fix bracket closed
86dd057 delete debug log.
24848df add FoundAction to open redirect results
f4ec2d7 Upgrade injection point logic / tap dev-2.2.0
b159382 Update optimization.go
24f4c5f Update issue templates
383d99d Update README.md
45395d7 Update README.md
1246ace Update README.md
3fa390c Update README.md
96db635 Update README.md
150b4bf Update README.md
1d23c83 Update README.md
912e7c6 Update README.md
d568de9 Update README.md
cc653a2 Update README.md
12fbefa Update README.md
e5c9e38 Update README.md
4dbeed8 Update README (#119)
554aab1 Update CONTRIBUTING.md
4d4c919 Update CONTRIBUTING.md
1dfdd7e Separating BAV logic individually
3411212 Release v2.2.0
a95110d More optimization to Optimizations!
3ba3402 Modify help message
64dc407 Merge pull request #122 from bp0lr/master
64eb641 Merge pull request #121 from bp0lr/master
4b42210 Merge pull request #119 from bp0lr/master
70b3182 Merge pull request #117 from jsav0/master
900d602 Merge branch 'master' of https://github.com/hahwul/dalfox
4188f71 Merge branch 'master' of https://github.com/hahwul/dalfox
6142792 Merge branch 'master' into master
d845dfe Improve optimization and new openRedirect BAV.
6ad927a Fix a bug on open redirector detection
ad8d6d6 Change log data
f8baabb Add --port, --host flag in server mode
055a68b Add --port, --host flag in server mode
cd65ac0 (Fixed #126) Added --skip-something notation
7ce564a (Fixed #125) Changed --follow-redirects coe
527cff1 (Closed #113) Upgrade reflection check logic using Abstraction of injection point
25aae9b (#121) Remove to code incorrectly reflected during collision fix
11814c9 (#119) Make BAV(Basic Another Vulnerability) Analysis
b7d21a6 (#119) Change code for concurrency / Add 'done' log
48d696c (#119) Add --no-bav options / switch bav, default is false(using bav)
080aa98 #113 Upgrade injection point logic / tap dev-2.2.0
597ae6e #113 Upgrade injection point logic

dalfox - v2.1.2

Published by hahwul about 4 years ago

Changelog

0c307f8 (Fixed #112) Change snapcraft confinement and plugs / release 2.1.2
e0f1646 (Fixed #112) Change snapcraft confinement and plugs / release 2.1.2
45c3b6a (Fixed #112) Change snapcraft confinement and plugs / release 2.1.2

dalfox - v2.1.1

Published by hahwul about 4 years ago

Changelog

5c5c4b9 Release 2.1.1
8617c49 (Fixed #111) Bug fix

dalfox - v2.1.0

Published by hahwul about 4 years ago

Changelog

2a910a1 update
9586998 remove comments
2dcc365 release 2.1.0
862b97c Update module labstack/echo/v4 to v4.1.17
f0b886c Update README.md
f8486e9 Update README.md
9b8991b Update README.md
57a1826 Update README.md
c541fcb Update README.md
b77c1a0 Update README.md
ee802ea Update README.md
c68eb2a Update README.md
f871186 Update README.md
b65f6dc Update README.md
4674e72 Update README.md
9604e86 Update README.md
19864fc Merge pull request #105 from hahwul/renovate/github.com-labstack-echo-v4-4.x
1ac315b Merge branch 'master' of https://github.com/hahwul/dalfox
6cb73b5 Merge branch 'master' of https://github.com/hahwul/dalfox
ae320e8 Merge branch 'master' of https://github.com/hahwul/dalfox
6d151d4 Create CONTRIBUTING.md
96c26e1 Code quality improvement (modify codacy issues)
578ea71 Code quality improvement (modify codacy issues)
f10462f Code quality improvement (modify codacy issues)
61701ab Change description
7d68212 Add system log(mining options)
0fa6e68 (Closed #92) Change PoC Printing(Show pattern name in built-in greppring)
6b76fee (Closed #92) Add built-in grep rule from sample rule
856f279 (Closed #109,#110) Add -X / --method option and logic, add attr of log format
0aaaae5 (Closed #108) Add no-color option
fe2acd7 (#103) add it / (#106) Add concurrency in parameter analysis
9443a18 (#103) Add param mining(with gf-partterns)
fa39d55 (#103) Add --mining , mining-word options
090caf0 (#103) Add --mining , mining-word options
d3aebf3 (#101) Add pattern of ignore content-type
de1c14a #110 Change log format
820caf4 #109 Add -X --method cmd
af23c11 #109 Add -X --method cmd
58ba6ac #104 Add --no-spinner option
25d368d #103 change mining options names and new option
5a65dff #103 Add DOM Mining(hidden param) pattern
add6d4a #103 Add DOM Mining(hidden param)

dalfox - v2.0.2

Published by hahwul about 4 years ago

Changelog

61b6094 release v2.0.2
447cf1f go verion change (1.14 to 1.15)
b64cb65 Update go.yml
e05e847 Modify template text
c57c0f3 Add event handler (ondurationchange)
fe68d73 Add XSS Payloads
112484f #100 change health check http object

dalfox - v2.0.1

Published by hahwul about 4 years ago

Changelog

f782438 release v2.0.1
fd6460b change inJS level, vuln to weak / Use payloads like polyglot to reduce false positive in JS point
4dc859c change inJS level, vuln to weak
fadf25b Update sample
0af4c7f Update greetings
dec73fb Update golang Docker tag to v1.15
f17e21e Update README.md
5c74526 Merge pull request #93 from hahwul/renovate/docker-golang-1.x
b291ea7 Merge branch 'master' of https://github.com/hahwul/dalfox
f7d2aac Merge branch 'master' of https://github.com/hahwul/dalfox
2dac690 (Closed #95) Add onshow entity / from https://twitter.com/PortSwiggerRes/status/1293894195393056770

dalfox - v2.0.0

Published by hahwul about 4 years ago

Changelog

71ce5d1 update grepping
6fc77d6 remove snap workflow, modify other CI yml
15c1125 remove release script (script => goreleaser)
4b959bb remove go selfupdate
a0a4759 for code quality
414e95b change log message
c8783d0 change log format
73807c4 change echo version none => v4
aceaf37 change dev version
6094313 change default worker number
8fa5f3e change color
005b481 add version color
5f5e182 Update server model
d9f8348 Update server model
0719313 Update module logrusorgru/aurora to v3
f2d9500 Update module labstack/echo/v4 to v4.1.16
1c75a3e Update module blang/semver to v4
394d6e6 Update module blang/semver to v3.8.0
a3a421b Update issue templates
2f9c4af Update issue templates
6ac3640 Update issue templates
242c8df Update go.mod
4c8a031 Update go.mod
5b6b5d4 Update README.md
cceeef5 Update README.md
01385bf Update README.md
3a9e741 Update README.md
71d97b2 Update README.md
85e27ff Update FUNDING.yml
6a6a688 Update FUNDING.yml
b60e32b Update
f27bf59 Merge pull request #89 from hahwul/renovate/github.com-logrusorgru-aurora-3.x
a5a9bbf Merge pull request #86 from hahwul/renovate/github.com-blang-semver-4.x
4cac6db Merge pull request #85 from hahwul/renovate/github.com-labstack-echo-v4-4.x
6584fcc Merge pull request #84 from hahwul/renovate/github.com-blang-semver-3.x
c2a1b9e Merge pull request #83 from hahwul/renovate/configure
11ddf00 Merge branch 'master' of https://github.com/hahwul/dalfox
bbbb917 Merge branch 'master' of https://github.com/hahwul/dalfox
5af391d Create greetings.yml
72eaaa7 Create SECURITY.md
7ce8563 Create CODE_OF_CONDUCT.md
ab72fb7 Change swagger
d2a4cf9 Add swagger
5214b98 Add renovate.json
2310ac8 Add log message
3aa247b Add Server mode
dae34a8 Add MakeHeaderQuery()
9054512 Add MakeHeaderQuery()
300f231 Add 'show amount of urls scanned out of total amount of given urls' on file/pipe mode
a8c944b (Closed #91) Remove duplicated on grep options
5037f4d (Closed #90) Add GET /scans
2318d1b (Closed #88) Code Refactoring
128106e (Closed #82) Add API Server
f7b18b4 (Closed #80, #81) Release 2.0
b29c4ab (Closed #56) Add follow-redirects flag(default false)
31450c7 (#88) Change config sample data
839d435 (#79) Change logger and --format option
1bb947c (#79) Change logger (silence option)
a7ad34e (#78) Blind XSS with header
5467696 #79 , #81 Change spinner char and Add stderr writer
d9477ab #79 , #81 Change log format
7fcabd6 #79 , #81 Change log format

dalfox - v1.2.1

Published by hahwul about 4 years ago

Changelog

0f0dc62 test goreleaser
e379569 test goreleaser
b3eb56c test goreleaser
54836a1 test goreleaser
b8cfe01 Update docker-image.yml
b9641e8 Update docker-image.yml
7b51652 Update README.md
03b7345 Update README.md
e5c7685 Create docker-image.yml
0e3439c Add goreleaser
ab43e06 Add gitaction snapcraft
cafffb9 Add gitaction snapcraft
56c3c3f Add dockerfile
861a40e Add dockerfile
57ee34e Add dockerfile

dalfox - v1.2.0

Published by hahwul over 4 years ago

Add --multicast flag on file and pipe mode.
This flag is an option for simultaneous testing of multiple hosts, and testing multiple hosts by grouping the target url on a per-host basis. Because simultaneous testing is performed on a per-host basis, each host is under the same load as an existing scan and can significantly reduce overall scanning time.
(High Performance option)

dalfox - v1.1.3

Published by hahwul over 4 years ago

  • Add defense code in blind xss(branch logic.)
  • Fixed bugs
dalfox - v1.1.2

Published by hahwul over 4 years ago

  • Modify usage
dalfox - v1.1.1

Published by hahwul over 4 years ago

  • Add blind XSS pattern and change logic
  • Fixed bug