Find XSS the easy way! Dalfox - Hacker Tools

Поделиться
HTML-код
  • Опубликовано: 11 сен 2024

Комментарии • 63

  • @user-vg8ve7zf7e
    @user-vg8ve7zf7e 2 года назад +5

    This is the best xs software i have ever seen
    I really feel great!

    • @intigriti
      @intigriti  2 года назад +1

      Great! Any cool finds with it yet?

  • @youngheej8432
    @youngheej8432 3 года назад +2

    So cool hahwul!!!!!!!!!

    • @intigriti
      @intigriti  3 года назад

      We also like him 😇

  • @william_ade
    @william_ade 2 года назад +1

    Thanks really appreciated!

  • @tomjohnes5030
    @tomjohnes5030 2 года назад +2

    This is definitely fire. But how to we hide its signature ? I see Dalfox populated on my testing machine logs. Not stealthy

    • @intigriti
      @intigriti  2 года назад +1

      It is most likely the user-agent that your seeing. Check the Dalfox help page to look up how to change it!

  • @tbjehad106
    @tbjehad106 8 месяцев назад

    why i didn't get the ditails over view step by step after scan. it just says issue 6 thats it .but didn't said me the vulnerability, the step and payload the tool user for to find this . but in this video you shows us its tell all the step

  • @malikimranawan3762
    @malikimranawan3762 3 года назад +3

    Can it work in finding real bug ?
    Bcz finding Bugs manually is much difficult ...

    • @intigriti
      @intigriti  3 года назад +1

      It can definitely help you!

    • @jimgrayson4828
      @jimgrayson4828 Год назад

      Think locally bro not just wan think Lan

  • @CameronNoakes
    @CameronNoakes 2 года назад +1

    I can't run the tool how do you run it I get dalfox not a command

    • @intigriti
      @intigriti  2 года назад

      You first need to install dalfox. Look at the blog post in the description to find out how!

  • @Life-M77
    @Life-M77 2 года назад +1

    Super sir

  • @rookie1913
    @rookie1913 3 года назад +1

    Great~

  • @hahwul
    @hahwul 3 года назад +3

    😍😎

    • @intigriti
      @intigriti  3 года назад +1

      Thanks for the amazing tool!

  • @gurvirsingh4190
    @gurvirsingh4190 3 года назад

    Great 🔥

    • @intigriti
      @intigriti  3 года назад

      Thanks!! 🔥

    • @jishan3201
      @jishan3201 2 года назад

      @Gurvir singh Bhai har jagah yahi comment karte ho kya.. 😀😀😀 .

  • @itsm3dud39
    @itsm3dud39 2 года назад +1

    can you suggest some other tools like this?

    • @intigriti
      @intigriti  2 года назад +1

      We'll cover some more in the future!

    • @itsm3dud39
      @itsm3dud39 2 года назад +1

      @@intigriti ok

  • @Dhruv-te6dy
    @Dhruv-te6dy Год назад

    in video you say file containing all your endpoints means all URLs with parameters am i right? (time stamp 04:50)

    • @intigriti
      @intigriti  Год назад

      Hmmm I didn't make this video so not 100% but generally when we say endpoint it's like "login endpoint = /login", "register endpoint = /register", "api endpoint = /api" etc

    • @Dhruv-te6dy
      @Dhruv-te6dy Год назад

      @@intigriti ok got it thanks

  • @william_ade
    @william_ade 2 года назад

    What bistro of Linux are u using (love it) ?

    • @intigriti
      @intigriti  2 года назад

      I'm using Kali Linux!

  • @lethalleet
    @lethalleet 3 года назад +1

    First comment again 🔥

    • @intigriti
      @intigriti  3 года назад +1

      Legend!

    • @lethalleet
      @lethalleet 3 года назад

      I need virtual tour of Intigriti office 🌞

  • @meljithpereira5532
    @meljithpereira5532 3 года назад +1

    Y you dalfox is so fast ..??

    • @intigriti
      @intigriti  3 года назад

      Hi, for more information on the internals of the tool, feel free to check out the GitHub page and ask there!

  • @ratmoneyg
    @ratmoneyg Год назад

    Does this still work?

    • @intigriti
      @intigriti  Год назад

      The repo is still active, so if it's not working you can always raise an issue: github.com/hahwul/dalfox/issues

    • @ratmoneyg
      @ratmoneyg Год назад

      @@intigriti yeah I just can’t figure out how to install it. I tried for a while yesterday but gave up lol

  • @techfunky9583
    @techfunky9583 2 года назад

    Bruh how to run the assetfinder command

    • @intigriti
      @intigriti  2 года назад

      What timestamp are you referring to?

  • @mukto2004
    @mukto2004 Год назад

    Does it also work with xss in input forms? Like comment

    • @intigriti
      @intigriti  Год назад

      As far as I'm aware, it does!

    • @Dhruv-te6dy
      @Dhruv-te6dy Год назад +1

      @@intigriti but how can you give some example for it ?

    • @intigriti
      @intigriti  Год назад

      check this example: media.geeksforgeeks.org/wp-content/uploads/20210723203017/Example1minmin.jpg which came from www.geeksforgeeks.org/dalfox-parameter-analysis-and-xss-scanning-tool

  • @learnfirst-1
    @learnfirst-1 2 года назад

    it dosen't found xss hard challanges ...🤣🤣 specially html encoding or other escape function

    • @intigriti
      @intigriti  2 года назад

      Yes, true. That's normal, no tool would be able to solve those!

  • @som3one01
    @som3one01 Год назад

    it is not accurate

    • @intigriti
      @intigriti  Год назад

      I'm sorry! What's not accurate?

    • @som3one01
      @som3one01 Год назад

      @@intigriti result

  • @AkashPatel-zd4wf
    @AkashPatel-zd4wf 6 месяцев назад

    one of the worst tool i ever encounter in bug bounty

  • @Free.Education786
    @Free.Education786 2 года назад +1

    What to do after getting alert(XSS); pop-up because pop-up with cookies 🍪 or document.domain(); pop-up is not suitable to receive bug bounty rewards. Please guide how to escalate reflected XSS to higher levels to earn bounties on hackerOne BugCrowd intigrity etc. Thanks 😊 🤝❤️💫💐😘🥰🌺💥💯👍

    • @intigriti
      @intigriti  2 года назад +1

      Unless on a sandbox domain or static page, an XSS should allow you to get a bounty on Intigriti.

  • @writecode9932
    @writecode9932 3 года назад

    Nice one... Thanks for sharing (rahulsl)

    • @intigriti
      @intigriti  3 года назад

      Glad you liked it! 😇

  • @jishan3201
    @jishan3201 2 года назад

    I scan testvul.php site with gau which gave me 2800 urls then scan all those with kxss which gave me 19 vulnerable urls which I gave them to dalfox but it did not find anything. I checked manualy and they were all vunerable. Why this happend. Is this tool realy helpfull.?

    • @intigriti
      @intigriti  2 года назад

      Be sure to submit this to the tool's GitHub page, so the creator can use it to improve the tool!