ffuf: Fast Web Fuzzer for Content Discovery and Vulnerability Research

ffuf (Fuzz Faster U Fool) is a rapid web fuzzer written in Go, primarily used for web content discovery (directories, files, subdomains, parameters) and vulnerability research. It works by replacing a FUZZ keyword in URLs, headers, or POST data with values from a wordlist, and then analyzing the responses.

Key Concepts

  • FUZZ keyword: This is the placeholder in your request that ffuf replaces with values from your wordlist.
  • Wordlists (-w): Files containing lists of words, paths, or subdomains to test.
  • Auto-Calibration (-ac): The -ac flag (auto-calibrate) is highly recommended. ffuf will first make some requests with dummy values to identify a “normal” response (e.g., a 404 page). It then automatically filters out responses that match this “normal” behavior, helping to reduce noise (false positives) and highlight interesting results.

Examples: Content and Subdomain Enumeration

1. Subdomain Enumeration via Host Header Fuzzing

This technique uses the FUZZ keyword in the Host header to test for virtual hosts or subdomains.

ffuf -ac -w SecLists/Discovery/DNS/subdomains-top1million-5000.txt -H "Host: FUZZ.target.com" -u http://target.com
  • -w <wordlist>: Specifies the wordlist (subdomains-top1million-5000.txt).
  • -H "Host: FUZZ.target.com": Fuzzes the Host header with wordlist entries prefixed to target.com.
  • -u http://target.com: The base URL to send requests to.

2. Basic Path/Directory Enumeration

This is a common use case to find hidden directories or files on a web server.

ffuf -ac -u https://<target.com>/FUZZ -w SecLists/Discovery/Web-Content/common.txt
# Example with a specific wordlist for WordPress
ffuf -ac -u https://www.example.com/FUZZ -w SecLists/Discovery/Web-Content/URLs/urls-wordpress-3.3.1.txt
  • -u https://<target.com>/FUZZ: The URL where the path part (FUZZ) will be replaced by wordlist entries.

3. Fuzzing from a Domain List (Advanced)

This example demonstrates how to use one wordlist (livedomains.txt) to provide target domains and another (LinuxFileList.txt) to fuzz paths on each of those domains. The HOST keyword acts as a placeholder for the domain from the first wordlist.

ffuf -w ../wordlists/SecLists/Discovery/Web-Content/LinuxFileList.txt -w livedomains.txt:HOST -u HOST/FUZZ
  • -w livedomains.txt:HOST: livedomains.txt is assigned to the HOST keyword. Each entry from livedomains.txt will replace HOST in the URL.
  • -u HOST/FUZZ: The URL structure. For each HOST (domain), FUZZ (from LinuxFileList.txt) will be tested.

Other Useful Flags

  • -mc 200,301,302: Match only specific HTTP status codes (e.g., success codes).
  • -fc 404: Filter out specific HTTP status codes (e.g., Not Found).
  • -fl <num>: Filter by line count.
  • -fw <num>: Filter by word count.
  • -fs <num>: Filter by size.
  • -e .php,.bak,.zip: Append extensions to words from the wordlist.

Disclaimer: ffuf is a powerful tool. Its use should be restricted to legal and ethical purposes, such as authorized penetration testing, bug bounty hunting on explicitly allowed scopes, or security research on systems you own or have explicit permission to test. Unauthorized scanning and fuzzing of web applications are illegal and unethical.