web-tool-wfuzz.md (8987B)
1 --- 2 title: "Web Tool - WFuzz" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/web-tool-wfuzz.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/web-tool-wfuzz.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Web Tool - WFuzz 14 15 A tool to FUZZ web applications anywhere. 16 17 > [Wfuzz](https://github.com/xmendez/wfuzz) has been created to facilitate the task in web applications assessments and it is based on a simple concept: it replaces any reference to the FUZZ keyword by the value of a given payload. 18 19 ## Installation 20 21 Installed in Kali: 22 23 ```bash 24 sudo apt install wfuzz 25 pip install -U wfuzz 26 # Docker image 27 # docker run -v $(pwd)/wordlist:/wordlist/ -it ghcr.io/xmendez/wfuzz wfuzz 28 ``` 29 30 Github: [https://github.com/xmendez/wfuzz](https://github.com/xmendez/wfuzz) 31 32 > If `pip install wfuzz` breaks in recent Python environments, upgrade to the latest upstream release first (`pip install -U wfuzz`).<sup>[[1]](#references)</sup> 33 34 ## Filtering options 35 36 ```bash 37 --hs/ss "regex" # Hide/Show by regex in response body 38 # Simple example, match a string: "Invalid username" 39 # Regex example: "Invalid .*" 40 41 --hc/sc CODE # Hide/Show by code in response 42 --hl/sl NUM # Hide/Show by number of lines in response 43 --hw/sw NUM # Hide/Show by number of words in response 44 --hh/sh NUM # Hide/Show by number of chars in response 45 46 --filter "c=200 and h!=BBB" # Expression filter (check: wfuzz --filter-help) 47 # c,l,w,h are response code, lines, words and chars 48 # BBB means: use the baseline response value 49 ``` 50 51 ### Baseline filtering (`BBB`) 52 53 Very useful when the application answers every invalid request with the **same** `200`, `302` or custom error page. 54 55 ```bash 56 # Baseline the response using a value that should not exist 57 wfuzz -c -w /usr/share/seclists/Discovery/Web-Content/common.txt \ 58 --hc BBB http://target.tld/FUZZ{this-should-not-exist-123} 59 60 # Same idea, but keeping only responses that differ from the baseline in size 61 wfuzz -c -w users.txt -d 'username=FUZZ&password=invalid' \ 62 --filter 'c=200 and h!=BBB' http://target.tld/login.php 63 ``` 64 65 ## Output options 66 67 ```bash 68 wfuzz -e printers # Prints the available output formats 69 -f /tmp/output.csv,csv # Saves the output in csv format 70 -f /tmp/output.json,json # Saves the output in json format 71 -o json # Prints json to stdout 72 --efield r # Print extra fields (useful to inspect raw request) 73 --field url # Replace default payload column with a selected field 74 ``` 75 76 ## Useful advanced switches 77 78 ```bash 79 -R 1 # Recursive path discovery depth 80 -L # Follow HTTP redirections 81 -Z # Scan mode: don't abort on connection/DNS errors (errors become XXX) 82 -m zip # Pair payloads 1:1 instead of using the default cartesian product 83 -m chain # Use one payload after another 84 -V allvars # Fuzz all GET params without placing FUZZ in the URL 85 -V allpost # Fuzz all POST params without placing FUZZ in the body 86 --dump-recipe /tmp/wfuzz.rcp # Save a run for later reuse 87 --recipe /tmp/wfuzz.rcp # Re-run a saved recipe 88 --ip 10.10.10.10 # Connect to a chosen IP while keeping the URL host 89 ``` 90 91 ### Encoders options 92 93 ```bash 94 wfuzz -e encoders # Prints the available encoders 95 # Examples: urlencode, md5, base64, hexlify, uri_hex, double urlencode 96 ``` 97 98 In order to use an encoder, you have to indicate it in the **`-w`** or **`-z`** option.<sup>[[2]](#references)</sup> 99 100 Examples: 101 102 ```bash 103 -z file,/path/to/file,md5 # Will use a list inside the file, and will transform each value into its md5 hash before sending it 104 -w /path/to/file,base64 # Will use a list, and transform to base64 105 -z list,each-element-here,hexlify # Inline list and to hex before sending values 106 ``` 107 108 You can also **chain** encoders and **combine payloads**: 109 110 ```bash 111 # Apply several encoders to the same payload source 112 wfuzz -z list,1-2-3,sha1-sha1@none http://example.com/FUZZ 113 114 # Pair usernames and passwords line-by-line instead of trying the full cartesian product 115 wfuzz -w users.txt -w passwords.txt -m zip \ 116 -d 'username=FUZZ&password=FUZ2Z' http://example.com/login 117 ``` 118 119 ## CheatSheet 120 121 ### Login Form bruteforce 122 123 #### **POST, Single list, filter string (hide)** 124 125 ```bash 126 wfuzz -c -w users.txt --hs "Login name" -d "name=FUZZ&password=FUZZ&autologin=1&enter=Sign+in" http://zipper.htb/zabbix/index.php 127 # Here we have filtered by regex in the response body 128 ``` 129 130 #### **POST, 2 lists, filter code (show)** 131 132 ```bash 133 wfuzz.py -c -z file,users.txt -z file,pass.txt --sc 200 -d "name=FUZZ&password=FUZ2Z&autologin=1&enter=Sign+in" http://zipper.htb/zabbix/index.php 134 # Here we have filtered by code 135 ``` 136 137 #### **POST, 2 paired lists (`zip` iterator)** 138 139 ```bash 140 wfuzz -c -w users.txt -w passwords.txt -m zip --sc 200 \ 141 -d 'username=FUZZ&password=FUZ2Z' http://example.com/login 142 ``` 143 144 #### **GET, 2 lists, filter string (show), proxy, cookies** 145 146 ```bash 147 wfuzz -c -w users.txt -w pass.txt --ss "Welcome " -p 127.0.0.1:8080:HTTP -b "PHPSESSIONID=1234567890abcdef;customcookie=hey" "http://example.com/index.php?username=FUZZ&password=FUZ2Z&action=sign+in" 148 ``` 149 150 #### **JSON API login / OTP bruteforce** 151 152 ```bash 153 wfuzz -c -z range,000000-999999 --hh BBB \ 154 -H 'Content-Type: application/json' \ 155 -d '{"username":"admin","otp":"FUZZ"}' \ 156 http://example.com/api/verify 157 ``` 158 159 ### Bruteforce Directory/RESTful bruteforce 160 161 [Arjun parameters wordlist](https://raw.githubusercontent.com/s0md3v/Arjun/master/arjun/db/params.txt) 162 163 ```bash 164 wfuzz -c -w /tmp/tmp/params.txt --hc 404 https://domain.com/api/FUZZ 165 ``` 166 167 ### Path Parameters BF 168 169 ```bash 170 wfuzz -c -w ~/git/Arjun/db/params.txt --hw 11 'http://example.com/path%3BFUZZ=FUZZ' 171 ``` 172 173 ### Fuzz all parameters automatically 174 175 ```bash 176 # Bruteforce every GET parameter value without placing FUZZ manually 177 wfuzz -c -z file,/usr/share/seclists/Fuzzing/LFI/LFI-Jhaddix.txt \ 178 -V allvars --hc 404 'http://example.com/index.php?file=1&page=2&lang=en' 179 180 # Same idea for POST bodies 181 wfuzz -c -z list,"1'-2'-3'" -V allpost \ 182 -d 'username=admin&password=test&otp=000000' \ 183 --ss 'SQL|syntax|warning' http://example.com/login 184 ``` 185 186 ### Header Authentication 187 188 #### **Basic, 2 lists, filter string (show), proxy** 189 190 ```bash 191 wfuzz -c -w users.txt -w pass.txt -p 127.0.0.1:8080:HTTP --ss "Welcome" --basic FUZZ:FUZ2Z "http://example.com/index.php" 192 ``` 193 194 #### **NTLM, 2 lists, filter string (show), proxy** 195 196 ```bash 197 wfuzz -c -w users.txt -w pass.txt -p 127.0.0.1:8080:HTTP --ss "Welcome" --ntlm 'domain\FUZZ:FUZ2Z' "http://example.com/index.php" 198 ``` 199 200 ### Cookie/Header bruteforce (vhost brute) 201 202 #### **Cookie, filter code (show), proxy** 203 204 ```bash 205 wfuzz -c -w users.txt -p 127.0.0.1:8080:HTTP --ss "Welcome " -H "Cookie:id=1312321&user=FUZZ" "http://example.com/index.php" 206 ``` 207 208 #### **User-Agent, filter code (hide), proxy** 209 210 ```bash 211 wfuzz -c -w user-agents.txt -p 127.0.0.1:8080:HTTP --ss "Welcome " -H "User-Agent: FUZZ" "http://example.com/index.php" 212 ``` 213 214 #### **Host** 215 216 ```bash 217 wfuzz -c -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-20000.txt \ 218 --hc 400,404,403 -H 'Host: FUZZ.example.com' -u http://example.com -t 100 219 ``` 220 221 #### **Host + explicit IP (reverse proxy / misrouting checks)** 222 223 ```bash 224 wfuzz -c -w vhosts.txt --ip 10.10.10.10 \ 225 --hc BBB -H 'Host: FUZZ.example.com' http://example.com/ 226 ``` 227 228 For more methodology around wildcard vhosts and related recon edge-cases, check [this page](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/external-recon-methodology/README.md). 229 230 ### HTTP Verbs (methods) bruteforce 231 232 #### **Using file** 233 234 ```bash 235 wfuzz -c -w methods.txt -p 127.0.0.1:8080:HTTP --sc 200 -X FUZZ "http://example.com/index.php" 236 ``` 237 238 #### **Using inline list** 239 240 ```bash 241 wfuzz -z list,GET-HEAD-POST-TRACE-OPTIONS -X FUZZ http://testphp.vulnweb.com/ 242 ``` 243 244 ### Directory & Files Bruteforce 245 246 ```bash 247 # Filter by whitelisting codes 248 wfuzz -c -z file,/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt --sc 200,202,204,301,302,307,403 http://example.com/uploads/FUZZ 249 ``` 250 251 ### Recursive discovery 252 253 ```bash 254 # Reuse the same payload inside discovered directories up to depth 2 255 wfuzz -c -w /usr/share/seclists/Discovery/Web-Content/common.txt \ 256 -R 2 --sc 200,301,302,307,403 http://example.com/FUZZ 257 ``` 258 259 ### Save / restore long fuzzing sessions 260 261 ```bash 262 wfuzz -c -w dirs.txt --hc 404 --dump-recipe /tmp/wfuzz.recipe http://example.com/FUZZ 263 wfuzz --recipe /tmp/wfuzz.recipe -b 'session=abc123' 264 ``` 265 266 ## Tool to bypass Webs 267 268 [https://github.com/carlospolop/fuzzhttpbypass](https://github.com/carlospolop/fuzzhttpbypass) 269 270 ## References 271 272 - [1] [Wfuzz - Releases](https://github.com/xmendez/wfuzz/releases) 273 - [2] [Wfuzz documentation - Advanced usage](https://wfuzz.readthedocs.io/en/latest/user/advanced.html)