← All cheat sheets

SFUZZ

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

sfuzz (Simple Fuzzer) is a simple, lightweight network protocol
fuzzer. It reads a configuration file defining the protocol
conversation and inserts fuzz strings at specified points to test
for vulnerabilities.

BASIC USAGE#

sfuzz -T -f <config> -S <target> -p <port>
                                 # TCP fuzzing
sfuzz -U -f <config> -S <target> -p <port>
                                 # UDP fuzzing

OPTIONS#

sfuzz -T                         # TCP mode
sfuzz -U                         # UDP mode
sfuzz -f <config>                # Configuration/script file
sfuzz -S <server>                # Target server IP
sfuzz -p <port>                  # Target port
sfuzz -L <file>                  # Log output to file
sfuzz -n <count>                 # Number of fuzz iterations
sfuzz -l <literal>               # Fuzz string literal
sfuzz -t <timeout>               # Connection timeout

CONFIGURATION FILE FORMAT#

# Config files define the protocol exchange:

# Comments start with #
# Lines define send/receive sequences:
# line=[send/recv] data_to_send_or_expect

# Example FTP fuzzer config:
# line=recv                       # Receive banner
# line=send USER FUZZ\r\n         # Send username with fuzz
# line=recv                       # Receive response
# line=send PASS test\r\n         # Send password
# line=recv                       # Receive response

# FUZZ keyword marks injection point

FUZZ STRINGS#

# sfuzz injects various payloads:
# - Long strings (A * N)
# - Format strings (%s, %n, %x)
# - Null bytes
# - Special characters
# - Boundary values
# - Custom literals via -l flag

EXAMPLES#

# Fuzz FTP server
sfuzz -T -f ftp.cfg -S 192.168.1.1 -p 21

# Fuzz HTTP server
sfuzz -T -f http.cfg -S 192.168.1.1 -p 80

# UDP fuzz with logging
sfuzz -U -f udp_service.cfg -S 192.168.1.1 -p 161 -L results.log

# Custom fuzz string
sfuzz -T -f smtp.cfg -S 192.168.1.1 -p 25 -l "AAAA%08x"

# Limited iterations
sfuzz -T -f ftp.cfg -S 192.168.1.1 -p 21 -n 100

CREATING CONFIG FILES#

# HTTP fuzzer example:
# ---
# line=send GET /FUZZ HTTP/1.1\r\n
# line=send Host: target\r\n
# line=send \r\n
# line=recv
# ---

# SMTP fuzzer example:
# ---
# line=recv
# line=send HELO FUZZ\r\n
# line=recv
# line=send MAIL FROM:<FUZZ@test.com>\r\n
# line=recv
# ---

NOTES#

- C-based, lightweight and fast
- Simple config file format
- Good for custom protocol fuzzing
- Supports TCP and UDP
- FUZZ keyword marks injection points
- Monitor target with debugger during testing
- Less feature-rich than boofuzz but simpler to use
- Good for quick, targeted fuzzing