DalFox - Parameter Analysis and XSS Scanning tool based on golang

(429 views)

DalFox - Finder of XSS, and Dal is the Korean pronunciation of the moon. What is DalFox Just, XSS scanning and parameter analysis tool. I previously developed XSpear, a ruby-based XSS tool, and this time, a full change occurred during the process of porting with golang!!! and created it as a new project. The basic concept is to analyze parameters, find XSS, and verify them based on DOM Parser. I talk about naming. Dal(달) is the Korean pronunciation of moon and fox was made into Fox(Find Of XSS). Key features Parameter Analysis (find the reflected parameter, find free/bad characters, Identification of injection point) Static Analysis (Check Bad-header like CSP, X-Frame-optiopns, etc.. with base request/response base) Optimization query of payloads Check the injection point through abstraction and generated the fit payload. Eliminate unnecessary payloads based on badchar XSS Scanning and DOM Base Verifying All test payloads(build-in, your custom/blind) are tested in....

May 15, 2020
Subscribe
Notify of
guest
1 Comment
Newest
Oldest Most Voted
Inline Feedbacks
View all comments
Hmm
Hmm
1 year ago

Heavy

Last edited 1 year ago by Hmm
© HAKIN9 MEDIA SP. Z O.O. SP. K. 2023
What certifications or qualifications do you hold?
Max. file size: 150 MB.
What level of experience should the ideal candidate have?
What certifications or qualifications are preferred?

Download Free eBook

Step 1 of 4

Name(Required)

We’re committed to your privacy. Hakin9 uses the information you provide to us to contact you about our relevant content, products, and services. You may unsubscribe from these communications at any time. For more information, check out our Privacy Policy.