How to Configure SOCKS5/TOR Proxy for Anonymized Scanning in SpiderFoot
SpiderFoot routes all HTTP requests through SOCKS4, SOCKS5, HTTP, or TOR proxies by setting five configuration options (_socks1type, _socks2addr, _socks3port, _socks4user, _socks5pwd) that propagate from sfscan.py through sflib.py into every requests.Session call.
SpiderFoot is an open-source intelligence (OSINT) automation platform by smicallef/spiderfoot that supports anonymous scanning via proxy routing. This guide explains how to configure SOCKS5 and TOR proxies using the command line, configuration files, or web interface, with technical details drawn directly from the source code.
SOCKS5/TOR Proxy Configuration Options
SpiderFoot defines five proxy-related options in the core configuration (sf.py):
| Option | Purpose | Valid Values |
|---|---|---|
_socks1type |
Proxy protocol type | 4, 5, HTTP, TOR |
_socks2addr |
Proxy server IP or hostname | e.g., 127.0.0.1 |
_socks3port |
Proxy server TCP port | 1080 (SOCKS4/5), 8080 (HTTP), 9050 (TOR) |
_socks4user |
Username for SOCKS authentication (optional) | e.g., myuser |
_socks5pwd |
Password for SOCKS5 authentication (optional) | e.g., mypass |
The socksProxy property is constructed as a URL string. For TOR, this becomes socks5h://127.0.0.1:9050; for SOCKS5 without remote hostname resolution, it uses socks5://.
Three Ways to Enable SOCKS5/TOR Proxy in SpiderFoot
Command-Line Configuration
Pass proxy options directly when launching sf.py:
sf.py -s example.com \
-o _socks1type=TOR \
-o _socks2addr=127.0.0.1 \
-o _socks3port=9050
Authenticated SOCKS5 example:
sf.py -s example.com \
-o _socks1type=5 \
-o _socks2addr=127.0.0.1 \
-o _socks3port=1080 \
-o _socks4user=myuser \
-o _socks5pwd=mypass
Configuration File Method
Edit your sfconfig.cfg (or equivalent JSON/YAML configuration) under the options section:
options:
_socks1type: TOR
_socks2addr: 127.0.0.1
_socks3port: 9050
Web UI Configuration
- Navigate to Advanced Settings in the SpiderFoot web interface.
- Set SOCKS Server Type to
TORor5. - Enter SOCKS Server IP Address:
127.0.0.1. - Enter SOCKS Server TCP Port:
9050for TOR. - Save and initiate your scan.
How Proxy Routing Works Internally
The SOCKS5/TOR proxy implementation spans three core files in smicallef/spiderfoot:
sfscan.py (lines 138-176) — Reads proxy options from self.__config and constructs the proxy URL:
# Proxy URL construction logic in sfscan.py
proxy_url = f"socks5h://{socks_addr}:{socks_port}" # for TOR
self.__sf.socksProxy = proxy_url
sf.py — Holds the global socksProxy attribute as part of the core SpiderFoot object options.
sflib.py (line 1268) — Injects the proxy into every HTTP request by updating the requests.Session proxies dictionary:
if self.socksProxy:
request_log.append(f"proxy={self.socksProxy}")
session.proxies.update({
"http": self.socksProxy,
"https": self.socksProxy,
})
All SpiderFoot modules inherit this proxy-aware request handling through the base class in plugin.py.
Verifying Proxy Activation
Check scan logs for the proxy indicator string. In sflib.py, successful proxy injection logs:
proxy=socks5h://127.0.0.1:9050
This confirms your SOCKS5/TOR anonymized scanning configuration is active.
Programmatic Configuration Example
For custom scripts using SpiderFoot as a library:
from spiderfoot import SpiderFoot
sf = SpiderFoot()
sf.opts['_socks1type'] = 'TOR'
sf.opts['_socks2addr'] = '127.0.0.1'
sf.opts['_socks3port'] = '9050'
sf.start()
Key Source Files for SOCKS5/TOR Proxy Support
| File | Role | Location |
|---|---|---|
sf.py |
Core class with global proxy options | sf.py |
sfscan.py |
Scan driver; builds proxy URL from config | sfscan.py |
sflib.py |
HTTP wrapper; applies proxy to all requests | sflib.py |
plugin.py |
Base module class inheriting proxy behavior | spiderfoot/plugin.py |
Summary
- Five options control proxy behavior:
_socks1type,_socks2addr,_socks3port,_socks4user,_socks5pwd. - Three activation methods: command-line flags, configuration file, or web UI Advanced Settings.
- Proxy URL construction happens in
sfscan.pyand propagates throughself.__sf.socksProxy. - Universal application via
sflib.pyupdatingrequests.Session.proxiesfor every module request. - Verification through log output showing
proxy=socks5h://...or equivalent.
Frequently Asked Questions
What is the difference between SOCKS5 and TOR proxy types in SpiderFoot?
SpiderFoot treats TOR as a specialized SOCKS5 variant that uses socks5h:// scheme for remote hostname resolution through the proxy, automatically defaulting to port 9050. Standard 5 uses socks5:// without forced remote DNS resolution. Both route traffic through your configured endpoint, but TOR simplifies setup for the standard TOR browser bundle configuration.
Does SpiderFoot support authenticated SOCKS5 proxies?
Yes. Set _socks4user for the username and _socks5pwd for the password. These credentials are embedded in the proxy URL as socks5://user:pass@host:port when both fields are populated, as handled in the proxy construction logic within sfscan.py.
Will all SpiderFoot modules use the configured proxy automatically?
Yes. The base SpiderFootPlugin class in plugin.py inherits request methods from the core sflib.py wrapper. Since sflib.py unconditionally applies session.proxies.update() whenever self.socksProxy exists, every module's HTTP requests—including DNS lookups passed through socks5h://—traverse the configured proxy without individual module changes.
Can I use an HTTP proxy instead of SOCKS5/TOR?
Yes. Set _socks1type to HTTP and configure _socks2addr and _socks3port accordingly (typically port 8080). The same internal mechanism constructs an http:// proxy URL rather than socks5:// or socks5h://.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →