ffuf
Fast web fuzzer for directories, files, vhosts, and parameters. The de-facto content discovery tool.
Tags: fuzzing, content-discovery, go, fast
- Category
- discovery
- Maintenance signal
- active
Project repository · Documentation
Use this when: Intake. Path names are a map. A 200 is not a finding by itself.
Install
go
go install github.com/ffuf/ffuf/v2@latestapt
sudo apt install -y ffufCommand templates
Directory brute
ffuf -u {url}/FUZZ -w {wordlist} -mc {codes} -o {output}VHost fuzz
ffuf -u {url} -H 'Host: FUZZ.{domain}' -w {wordlist} -fs {filtersize}