ffuf
go install github.com/ffuf/ffuf/v2@latestWordlist and keyword
ffuf -w /path/to/wordlist.txt:FUZZ -u http://TARGET/FUZZDirectory Fuzzing
ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt:FUZZ \
-u http://TARGET/FUZZ
# With status code filtering
ffuf -w wordlist.txt:FUZZ -u http://TARGET/FUZZ -mc 200,301,302File Fuzzing
Recursive Fuzzing
Parameter Fuzzing
GET Parameters
POST Parameters
JSON Body
VHost / Subdomain Fuzzing
Filtering Output
Match Filters (include results)
Flag
Description
Filter Filters (exclude results)
Flag
Description
Examples
Multiple Wordlists
Request from file (Burp / raw HTTP)
Authentication
Performance Options
Output
Proxy
HTTP Brute Force (Login Forms)
Manual Build (Correct Way)
Full Example
SQLi Discovery with ffuf
Password Wordlists
Common Wordlists
Quick Reference Commands
Last updated