SFUZZ
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
sfuzz (Simple Fuzzer) is a simple, lightweight network protocol fuzzer. It reads a configuration file defining the protocol conversation and inserts fuzz strings at specified points to test for vulnerabilities.
BASIC USAGE#
sfuzz -T -f <config> -S <target> -p <port>
# TCP fuzzing
sfuzz -U -f <config> -S <target> -p <port>
# UDP fuzzing
OPTIONS#
sfuzz -T # TCP mode sfuzz -U # UDP mode sfuzz -f <config> # Configuration/script file sfuzz -S <server> # Target server IP sfuzz -p <port> # Target port sfuzz -L <file> # Log output to file sfuzz -n <count> # Number of fuzz iterations sfuzz -l <literal> # Fuzz string literal sfuzz -t <timeout> # Connection timeout
CONFIGURATION FILE FORMAT#
# Config files define the protocol exchange: # Comments start with # # Lines define send/receive sequences: # line=[send/recv] data_to_send_or_expect # Example FTP fuzzer config: # line=recv # Receive banner # line=send USER FUZZ\r\n # Send username with fuzz # line=recv # Receive response # line=send PASS test\r\n # Send password # line=recv # Receive response # FUZZ keyword marks injection point
FUZZ STRINGS#
# sfuzz injects various payloads: # - Long strings (A * N) # - Format strings (%s, %n, %x) # - Null bytes # - Special characters # - Boundary values # - Custom literals via -l flag
EXAMPLES#
# Fuzz FTP server sfuzz -T -f ftp.cfg -S 192.168.1.1 -p 21 # Fuzz HTTP server sfuzz -T -f http.cfg -S 192.168.1.1 -p 80 # UDP fuzz with logging sfuzz -U -f udp_service.cfg -S 192.168.1.1 -p 161 -L results.log # Custom fuzz string sfuzz -T -f smtp.cfg -S 192.168.1.1 -p 25 -l "AAAA%08x" # Limited iterations sfuzz -T -f ftp.cfg -S 192.168.1.1 -p 21 -n 100
CREATING CONFIG FILES#
# HTTP fuzzer example: # --- # line=send GET /FUZZ HTTP/1.1\r\n # line=send Host: target\r\n # line=send \r\n # line=recv # --- # SMTP fuzzer example: # --- # line=recv # line=send HELO FUZZ\r\n # line=recv # line=send MAIL FROM:<FUZZ@test.com>\r\n # line=recv # ---
NOTES#
- C-based, lightweight and fast - Simple config file format - Good for custom protocol fuzzing - Supports TCP and UDP - FUZZ keyword marks injection points - Monitor target with debugger during testing - Less feature-rich than boofuzz but simpler to use - Good for quick, targeted fuzzing