FFUF
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
INSTALLATION#
go install github.com/ffuf/ffuf/v2@latest apt install ffuf # Kali Linux brew install ffuf # macOS
BASIC SYNTAX#
ffuf -u http://target.com/FUZZ -w wordlist.txt # FUZZ = placeholder for wordlist entries
COMMON OPTIONS#
-u URL Target URL with FUZZ keyword
-w WORDLIST Path to wordlist (or FUZZ:wordlist.txt)
-H HEADER HTTP header ("Name: Value")
-X METHOD HTTP method (GET, POST, PUT, etc.)
-d DATA POST data
-b COOKIES Cookie data
-t THREADS Number of threads (default 40)
-p DELAY Delay between requests (seconds)
-rate RATE Requests per second
-timeout SECONDS HTTP request timeout
-r Follow redirects
-recursion Enable recursion
-recursion-depth N Maximum recursion depth
-v Verbose output
-s Silent mode
-o OUTPUT Output file
-of FORMAT Output format (json, csv, html, md, all)
FILTERING OPTIONS#
# Match (show only) -mc CODES Match HTTP status codes (default: 200,204,301,302,307,401,403,405,500) -ml LINES Match by number of lines -mw WORDS Match by number of words -ms SIZE Match by response size -mr REGEX Match by regex in response -mt TIME Match by response time # Filter (hide) -fc CODES Filter HTTP status codes -fl LINES Filter by number of lines -fw WORDS Filter by number of words -fs SIZE Filter by response size -fr REGEX Filter by regex in response -ft TIME Filter by response time
DIRECTORY BRUTEFORCE#
# Basic directory scan ffuf -u http://target.com/FUZZ -w /usr/share/wordlists/dirb/common.txt # With extensions ffuf -u http://target.com/FUZZ -w wordlist.txt -e .php,.html,.txt,.bak # Filter 404 responses ffuf -u http://target.com/FUZZ -w wordlist.txt -fc 404 # Match specific size ffuf -u http://target.com/FUZZ -w wordlist.txt -ms 0-100 # Recursive scanning ffuf -u http://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 2
FILE DISCOVERY#
# Find backup files ffuf -u http://target.com/FUZZ -w wordlist.txt -e .bak,.old,.backup,~,.swp # Multiple extensions ffuf -u http://target.com/FUZZ -w wordlist.txt -e .php,.html,.js,.txt,.xml,.json
SUBDOMAIN ENUMERATION#
ffuf -u http://FUZZ.target.com -w subdomains.txt ffuf -u http://FUZZ.target.com -w subdomains.txt -H "Host: FUZZ.target.com" # Filter by size to remove wildcards ffuf -u http://FUZZ.target.com -w subdomains.txt -fs 1234
VHOST DISCOVERY#
ffuf -u http://target.com -H "Host: FUZZ.target.com" -w subdomains.txt ffuf -u http://target.com -H "Host: FUZZ.target.com" -w subdomains.txt -fs 0
PARAMETER FUZZING#
# GET parameter names ffuf -u http://target.com/page?FUZZ=value -w params.txt # GET parameter values ffuf -u http://target.com/page?param=FUZZ -w values.txt # POST parameter names ffuf -u http://target.com/page -X POST -d "FUZZ=value" -w params.txt # POST parameter values ffuf -u http://target.com/page -X POST -d "param=FUZZ" -w values.txt
MULTIPLE WORDLISTS#
# Two positions ffuf -u http://target.com/FUZZ1/FUZZ2 -w users.txt:FUZZ1 -w ids.txt:FUZZ2 # Username:password bruteforce ffuf -u http://target.com/login -X POST -d "user=FUZZ1&pass=FUZZ2" -w users.txt:FUZZ1 -w passwords.txt:FUZZ2 -fc 401 # Clusterbomb mode (all combinations) ffuf -u http://target.com/FUZZ1/FUZZ2 -w list1.txt:FUZZ1 -w list2.txt:FUZZ2 -mode clusterbomb # Pitchfork mode (parallel) ffuf -u http://target.com/FUZZ1/FUZZ2 -w list1.txt:FUZZ1 -w list2.txt:FUZZ2 -mode pitchfork
HTTP AUTHENTICATION#
# Basic auth ffuf -u http://target.com/FUZZ -w wordlist.txt -H "Authorization: Basic BASE64" # Bearer token ffuf -u http://target.com/FUZZ -w wordlist.txt -H "Authorization: Bearer TOKEN" # Cookie auth ffuf -u http://target.com/FUZZ -w wordlist.txt -b "session=abc123"
JSON FUZZING#
# JSON body
ffuf -u http://target.com/api -X POST -H "Content-Type: application/json" -d '{"param":"FUZZ"}' -w wordlist.txt
# JSON parameter discovery
ffuf -u http://target.com/api -X POST -H "Content-Type: application/json" -d '{"FUZZ":"value"}' -w params.txt
API TESTING#
# REST API endpoints ffuf -u http://target.com/api/FUZZ -w api-endpoints.txt # API versioning ffuf -u http://target.com/api/vFUZZ/users -w versions.txt # API methods ffuf -u http://target.com/api/users -X FUZZ -w methods.txt -mc all
RATE LIMITING#
# Limit requests per second ffuf -u http://target.com/FUZZ -w wordlist.txt -rate 10 # Delay between requests ffuf -u http://target.com/FUZZ -w wordlist.txt -p 0.5 # Reduce threads ffuf -u http://target.com/FUZZ -w wordlist.txt -t 5
OUTPUT#
# JSON output ffuf -u http://target.com/FUZZ -w wordlist.txt -o results.json -of json # HTML output ffuf -u http://target.com/FUZZ -w wordlist.txt -o results.html -of html # CSV output ffuf -u http://target.com/FUZZ -w wordlist.txt -o results.csv -of csv # All formats ffuf -u http://target.com/FUZZ -w wordlist.txt -o results -of all
PROXY#
# Through Burp ffuf -u http://target.com/FUZZ -w wordlist.txt -x http://127.0.0.1:8080 # Replay through proxy ffuf -u http://target.com/FUZZ -w wordlist.txt -replay-proxy http://127.0.0.1:8080
PRACTICAL EXAMPLES#
# Basic directory bruteforce ffuf -u http://target.com/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -fc 404 # Find hidden files ffuf -u http://target.com/FUZZ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt -e .php,.txt,.bak -fc 404 # Subdomain enumeration ffuf -u https://FUZZ.target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -fs 1234 # POST parameter fuzzing ffuf -u http://target.com/login -X POST -d "username=admin&password=FUZZ" -w passwords.txt -fc 401 # API endpoint discovery ffuf -u http://target.com/api/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -mc 200,201,204 # LFI testing ffuf -u "http://target.com/page?file=FUZZ" -w /usr/share/seclists/Fuzzing/LFI/LFI-gracefulsecurity-linux.txt -fs 0 # SQL injection testing ffuf -u "http://target.com/page?id=FUZZ" -w /usr/share/seclists/Fuzzing/SQLi/Generic-SQLi.txt -fs 1234
WORDLISTS#
/usr/share/seclists/Discovery/Web-Content/common.txt /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt /usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt /usr/share/seclists/Fuzzing/LFI/ /usr/share/seclists/Fuzzing/SQLi/ /usr/share/wordlists/dirb/common.txt /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
TIPS#
- Use -fc 404 to filter not found - Use -fs to filter by size (good for wildcards) - Use -mc all to match all status codes - Start with fewer threads (-t 10) for stability - Use -rate to avoid rate limiting - Save interesting results with -replay-proxy - Use -v for verbose troubleshooting - Combine with Burp for manual testing