Fuzzing: ffuf Tool
Install ffuf
$ sudo apt install ffuf$ ffuf -hInstall Latest Version
$ go install github.com/ffuf/ffuf@latest$ ~/go/bin/ffuf -hSimple ffuf Scan
$ ffuf -u https://codingo.io/FUZZ/ -w ./wordlistRecursion
$ ffuf -u https://codingo.io/FUZZ -w ./wordlist.txt -recursionExtension Checks
$ ffuf -u http://codingo.io/FUZZ -w ./wrodlist.txt -recursion -e .bakCustom Fuzzing Words
$ ffuf -u http://codingo.io/W1 -w ./wordlist.txt:W1 -e .bakSilent Mode and Tee for Output
Silent Mode
$ ffuf -u http://codingo.io/FUZZ -w ./wordlist.txt -sOutput Results
$ ffuf -u http://codingo.io/FUZZ -w ./wordlist.txt -s | tee ./outfile.txtHTML Output
$ ffuf -u http://codingo.io/FUZZ -w ./wordlist.txt -of html -o ./codingoFilters and Matches
$ ffuf -hAuthentication: Cookies
$ ffuf -u http://codingo.io/FUZZ -w ./wordlist.txt -of html -o ./codingo -b "NAME1=VALUE1; NAME2=VALUE2"Authentication: Headers
$ ffuf -u http://codingo.io/FUZZ -w ./wordlist.txt -of html -o ./codingo -H "NAME1=VALUE1; NAME2=VALUE2"Authentication via Burp Suite
Multiple Fuzzing Locations
$ ffuf -u https://W2.io/W1 -w ./wordlist.txt:W1 -w ./domains.txt:W2Importing Requests
$ ffuf -request /tmp/request -w ./wordlist.txtWordlist Modes
Stop on Spurious Errors

Queue Wide Rate Limiting

Automatic Calibration Mode

Replay Proxy (Local)
$ ffuf -u https://codingo.io/FUZZ -w ./wordlist.txt --replay-proxy http://127.0.0.1:8080Replay Proxy (Remote)
$ ffuf -u http://codingo.io/FUZZ -w ./wordlist.txt -replay-proxy http://127.0.0.1:8888END
Last updated
Was this helpful?
