← All cheat sheets

FFUF

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

INSTALLATION#

go install github.com/ffuf/ffuf/v2@latest
apt install ffuf       # Kali Linux
brew install ffuf      # macOS

BASIC SYNTAX#

ffuf -u http://target.com/FUZZ -w wordlist.txt
# FUZZ = placeholder for wordlist entries

COMMON OPTIONS#

-u URL              Target URL with FUZZ keyword
-w WORDLIST         Path to wordlist (or FUZZ:wordlist.txt)
-H HEADER           HTTP header ("Name: Value")
-X METHOD           HTTP method (GET, POST, PUT, etc.)
-d DATA             POST data
-b COOKIES          Cookie data
-t THREADS          Number of threads (default 40)
-p DELAY            Delay between requests (seconds)
-rate RATE          Requests per second
-timeout SECONDS    HTTP request timeout
-r                  Follow redirects
-recursion          Enable recursion
-recursion-depth N  Maximum recursion depth
-v                  Verbose output
-s                  Silent mode
-o OUTPUT           Output file
-of FORMAT          Output format (json, csv, html, md, all)

FILTERING OPTIONS#

# Match (show only)
-mc CODES           Match HTTP status codes (default: 200,204,301,302,307,401,403,405,500)
-ml LINES           Match by number of lines
-mw WORDS           Match by number of words
-ms SIZE            Match by response size
-mr REGEX           Match by regex in response
-mt TIME            Match by response time

# Filter (hide)
-fc CODES           Filter HTTP status codes
-fl LINES           Filter by number of lines
-fw WORDS           Filter by number of words
-fs SIZE            Filter by response size
-fr REGEX           Filter by regex in response
-ft TIME            Filter by response time

DIRECTORY BRUTEFORCE#

# Basic directory scan
ffuf -u http://target.com/FUZZ -w /usr/share/wordlists/dirb/common.txt

# With extensions
ffuf -u http://target.com/FUZZ -w wordlist.txt -e .php,.html,.txt,.bak

# Filter 404 responses
ffuf -u http://target.com/FUZZ -w wordlist.txt -fc 404

# Match specific size
ffuf -u http://target.com/FUZZ -w wordlist.txt -ms 0-100

# Recursive scanning
ffuf -u http://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 2

FILE DISCOVERY#

# Find backup files
ffuf -u http://target.com/FUZZ -w wordlist.txt -e .bak,.old,.backup,~,.swp

# Multiple extensions
ffuf -u http://target.com/FUZZ -w wordlist.txt -e .php,.html,.js,.txt,.xml,.json

SUBDOMAIN ENUMERATION#

ffuf -u http://FUZZ.target.com -w subdomains.txt
ffuf -u http://FUZZ.target.com -w subdomains.txt -H "Host: FUZZ.target.com"

# Filter by size to remove wildcards
ffuf -u http://FUZZ.target.com -w subdomains.txt -fs 1234

VHOST DISCOVERY#

ffuf -u http://target.com -H "Host: FUZZ.target.com" -w subdomains.txt
ffuf -u http://target.com -H "Host: FUZZ.target.com" -w subdomains.txt -fs 0

PARAMETER FUZZING#

# GET parameter names
ffuf -u http://target.com/page?FUZZ=value -w params.txt

# GET parameter values
ffuf -u http://target.com/page?param=FUZZ -w values.txt

# POST parameter names
ffuf -u http://target.com/page -X POST -d "FUZZ=value" -w params.txt

# POST parameter values
ffuf -u http://target.com/page -X POST -d "param=FUZZ" -w values.txt

MULTIPLE WORDLISTS#

# Two positions
ffuf -u http://target.com/FUZZ1/FUZZ2 -w users.txt:FUZZ1 -w ids.txt:FUZZ2

# Username:password bruteforce
ffuf -u http://target.com/login -X POST -d "user=FUZZ1&pass=FUZZ2" -w users.txt:FUZZ1 -w passwords.txt:FUZZ2 -fc 401

# Clusterbomb mode (all combinations)
ffuf -u http://target.com/FUZZ1/FUZZ2 -w list1.txt:FUZZ1 -w list2.txt:FUZZ2 -mode clusterbomb

# Pitchfork mode (parallel)
ffuf -u http://target.com/FUZZ1/FUZZ2 -w list1.txt:FUZZ1 -w list2.txt:FUZZ2 -mode pitchfork

HTTP AUTHENTICATION#

# Basic auth
ffuf -u http://target.com/FUZZ -w wordlist.txt -H "Authorization: Basic BASE64"

# Bearer token
ffuf -u http://target.com/FUZZ -w wordlist.txt -H "Authorization: Bearer TOKEN"

# Cookie auth
ffuf -u http://target.com/FUZZ -w wordlist.txt -b "session=abc123"

JSON FUZZING#

# JSON body
ffuf -u http://target.com/api -X POST -H "Content-Type: application/json" -d '{"param":"FUZZ"}' -w wordlist.txt

# JSON parameter discovery
ffuf -u http://target.com/api -X POST -H "Content-Type: application/json" -d '{"FUZZ":"value"}' -w params.txt

API TESTING#

# REST API endpoints
ffuf -u http://target.com/api/FUZZ -w api-endpoints.txt

# API versioning
ffuf -u http://target.com/api/vFUZZ/users -w versions.txt

# API methods
ffuf -u http://target.com/api/users -X FUZZ -w methods.txt -mc all

RATE LIMITING#

# Limit requests per second
ffuf -u http://target.com/FUZZ -w wordlist.txt -rate 10

# Delay between requests
ffuf -u http://target.com/FUZZ -w wordlist.txt -p 0.5

# Reduce threads
ffuf -u http://target.com/FUZZ -w wordlist.txt -t 5

OUTPUT#

# JSON output
ffuf -u http://target.com/FUZZ -w wordlist.txt -o results.json -of json

# HTML output
ffuf -u http://target.com/FUZZ -w wordlist.txt -o results.html -of html

# CSV output
ffuf -u http://target.com/FUZZ -w wordlist.txt -o results.csv -of csv

# All formats
ffuf -u http://target.com/FUZZ -w wordlist.txt -o results -of all

PROXY#

# Through Burp
ffuf -u http://target.com/FUZZ -w wordlist.txt -x http://127.0.0.1:8080

# Replay through proxy
ffuf -u http://target.com/FUZZ -w wordlist.txt -replay-proxy http://127.0.0.1:8080

PRACTICAL EXAMPLES#

# Basic directory bruteforce
ffuf -u http://target.com/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -fc 404

# Find hidden files
ffuf -u http://target.com/FUZZ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt -e .php,.txt,.bak -fc 404

# Subdomain enumeration
ffuf -u https://FUZZ.target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -fs 1234

# POST parameter fuzzing
ffuf -u http://target.com/login -X POST -d "username=admin&password=FUZZ" -w passwords.txt -fc 401

# API endpoint discovery
ffuf -u http://target.com/api/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -mc 200,201,204

# LFI testing
ffuf -u "http://target.com/page?file=FUZZ" -w /usr/share/seclists/Fuzzing/LFI/LFI-gracefulsecurity-linux.txt -fs 0

# SQL injection testing
ffuf -u "http://target.com/page?id=FUZZ" -w /usr/share/seclists/Fuzzing/SQLi/Generic-SQLi.txt -fs 1234

WORDLISTS#

/usr/share/seclists/Discovery/Web-Content/common.txt
/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
/usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt
/usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
/usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt
/usr/share/seclists/Fuzzing/LFI/
/usr/share/seclists/Fuzzing/SQLi/
/usr/share/wordlists/dirb/common.txt
/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt

TIPS#

- Use -fc 404 to filter not found
- Use -fs to filter by size (good for wildcards)
- Use -mc all to match all status codes
- Start with fewer threads (-t 10) for stability
- Use -rate to avoid rate limiting
- Save interesting results with -replay-proxy
- Use -v for verbose troubleshooting
- Combine with Burp for manual testing