← All cheat sheets

POWERFUZZER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Powerfuzzer is an automated web application fuzzer that tests for
common vulnerabilities including XSS, SQL injection, CRLF injection,
HTTP 500 errors, and more. It crawls web applications and fuzzes
discovered parameters.

BASIC USAGE#

powerfuzzer                      # Launch GUI
powerfuzzer -u <url>             # Fuzz target URL

OPTIONS#

powerfuzzer -u <url>             # Target URL
powerfuzzer -c <cookies>         # Set cookies
powerfuzzer -d <depth>           # Crawl depth
powerfuzzer -t <threads>         # Number of threads
powerfuzzer -o <output>          # Output directory
powerfuzzer -a <agent>           # Custom User-Agent
powerfuzzer -p <proxy>           # HTTP proxy

VULNERABILITY CHECKS#

# Cross-Site Scripting (XSS)
# - Reflected XSS
# - Various XSS payload variations

# SQL Injection
# - Error-based detection
# - Common SQL injection strings
# - Multiple DBMS support

# CRLF Injection
# - Header injection tests
# - HTTP response splitting

# HTTP 500 Errors
# - Server error triggering
# - Unhandled exception detection

# Path Traversal
# - Directory traversal attempts
# - File inclusion testing

# Command Injection
# - OS command injection
# - Various command separators

EXAMPLES#

# Basic web application fuzzing
powerfuzzer -u http://target.com/

# Fuzz with authentication cookies
powerfuzzer -u http://target.com/ -c "session=abc123"

# Deep crawl with more threads
powerfuzzer -u http://target.com/ -d 5 -t 10

# Fuzz through proxy (Burp Suite)
powerfuzzer -u http://target.com/ -p http://127.0.0.1:8080

# Save results to directory
powerfuzzer -u http://target.com/ -o /tmp/results

WORKFLOW#

# 1. Configure target URL
# 2. Set authentication if needed (cookies)
# 3. Set crawl depth and thread count
# 4. Start fuzzing
# 5. Monitor for discovered vulnerabilities
# 6. Verify findings manually
# 7. Generate report

NOTES#

- Python-based tool
- GUI and CLI modes
- Automatically crawls and discovers parameters
- Tests both GET and POST parameters
- Can be noisy (many requests)
- May trigger WAF rules
- Verify all findings manually
- Consider OWASP ZAP or Burp for more comprehensive testing