ffuf: Fast Web Fuzzer for Content Discovery and Vulnerability Research
ffuf (Fuzz Faster U Fool) is a rapid web fuzzer written in Go, primarily used for web content discovery (directories, files, subdomains, parameters) and vulnerability research. It works by replacing a FUZZ keyword in URLs, headers, or POST data with values from a wordlist, and then analyzing the responses.
Key Concepts
FUZZkeyword: This is the placeholder in your request thatffufreplaces with values from your wordlist.- Wordlists (
-w): Files containing lists of words, paths, or subdomains to test. - Auto-Calibration (
-ac): The-acflag (auto-calibrate) is highly recommended.ffufwill first make some requests with dummy values to identify a “normal” response (e.g., a 404 page). It then automatically filters out responses that match this “normal” behavior, helping to reduce noise (false positives) and highlight interesting results.
Examples: Content and Subdomain Enumeration
1. Subdomain Enumeration via Host Header Fuzzing
This technique uses the FUZZ keyword in the Host header to test for virtual hosts or subdomains.
ffuf -ac -w SecLists/Discovery/DNS/subdomains-top1million-5000.txt -H "Host: FUZZ.target.com" -u http://target.com-w <wordlist>: Specifies the wordlist (subdomains-top1million-5000.txt).-H "Host: FUZZ.target.com": Fuzzes theHostheader with wordlist entries prefixed totarget.com.-u http://target.com: The base URL to send requests to.
2. Basic Path/Directory Enumeration
This is a common use case to find hidden directories or files on a web server.
ffuf -ac -u https://<target.com>/FUZZ -w SecLists/Discovery/Web-Content/common.txt
# Example with a specific wordlist for WordPress
ffuf -ac -u https://www.example.com/FUZZ -w SecLists/Discovery/Web-Content/URLs/urls-wordpress-3.3.1.txt-u https://<target.com>/FUZZ: The URL where the path part (FUZZ) will be replaced by wordlist entries.
3. Fuzzing from a Domain List (Advanced)
This example demonstrates how to use one wordlist (livedomains.txt) to provide target domains and another (LinuxFileList.txt) to fuzz paths on each of those domains. The HOST keyword acts as a placeholder for the domain from the first wordlist.
ffuf -w ../wordlists/SecLists/Discovery/Web-Content/LinuxFileList.txt -w livedomains.txt:HOST -u HOST/FUZZ-w livedomains.txt:HOST:livedomains.txtis assigned to theHOSTkeyword. Each entry fromlivedomains.txtwill replaceHOSTin the URL.-u HOST/FUZZ: The URL structure. For eachHOST(domain),FUZZ(fromLinuxFileList.txt) will be tested.
Other Useful Flags
-mc 200,301,302: Match only specific HTTP status codes (e.g., success codes).-fc 404: Filter out specific HTTP status codes (e.g., Not Found).-fl <num>: Filter by line count.-fw <num>: Filter by word count.-fs <num>: Filter by size.-e .php,.bak,.zip: Append extensions to words from the wordlist.
Disclaimer: ffuf is a powerful tool. Its use should be restricted to legal and ethical purposes, such as authorized penetration testing, bug bounty hunting on explicitly allowed scopes, or security research on systems you own or have explicit permission to test. Unauthorized scanning and fuzzing of web applications are illegal and unethical.