daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

web-tool-wfuzz.md (8987B)


      1 ---
      2 title: "Web Tool - WFuzz"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/web-tool-wfuzz.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/web-tool-wfuzz.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Web Tool - WFuzz
     14 
     15 A tool to FUZZ web applications anywhere.
     16 
     17 > [Wfuzz](https://github.com/xmendez/wfuzz) has been created to facilitate the task in web applications assessments and it is based on a simple concept: it replaces any reference to the FUZZ keyword by the value of a given payload.
     18 
     19 ## Installation
     20 
     21 Installed in Kali:
     22 
     23 ```bash
     24 sudo apt install wfuzz
     25 pip install -U wfuzz
     26 # Docker image
     27 # docker run -v $(pwd)/wordlist:/wordlist/ -it ghcr.io/xmendez/wfuzz wfuzz
     28 ```
     29 
     30 Github: [https://github.com/xmendez/wfuzz](https://github.com/xmendez/wfuzz)
     31 
     32 > If `pip install wfuzz` breaks in recent Python environments, upgrade to the latest upstream release first (`pip install -U wfuzz`).<sup>[[1]](#references)</sup>
     33 
     34 ## Filtering options
     35 
     36 ```bash
     37 --hs/ss "regex" # Hide/Show by regex in response body
     38 # Simple example, match a string: "Invalid username"
     39 # Regex example: "Invalid .*"
     40 
     41 --hc/sc CODE # Hide/Show by code in response
     42 --hl/sl NUM  # Hide/Show by number of lines in response
     43 --hw/sw NUM  # Hide/Show by number of words in response
     44 --hh/sh NUM  # Hide/Show by number of chars in response
     45 
     46 --filter "c=200 and h!=BBB" # Expression filter (check: wfuzz --filter-help)
     47 # c,l,w,h are response code, lines, words and chars
     48 # BBB means: use the baseline response value
     49 ```
     50 
     51 ### Baseline filtering (`BBB`)
     52 
     53 Very useful when the application answers every invalid request with the **same** `200`, `302` or custom error page.
     54 
     55 ```bash
     56 # Baseline the response using a value that should not exist
     57 wfuzz -c -w /usr/share/seclists/Discovery/Web-Content/common.txt \
     58   --hc BBB http://target.tld/FUZZ{this-should-not-exist-123}
     59 
     60 # Same idea, but keeping only responses that differ from the baseline in size
     61 wfuzz -c -w users.txt -d 'username=FUZZ&password=invalid' \
     62   --filter 'c=200 and h!=BBB' http://target.tld/login.php
     63 ```
     64 
     65 ## Output options
     66 
     67 ```bash
     68 wfuzz -e printers              # Prints the available output formats
     69 -f /tmp/output.csv,csv         # Saves the output in csv format
     70 -f /tmp/output.json,json       # Saves the output in json format
     71 -o json                        # Prints json to stdout
     72 --efield r                     # Print extra fields (useful to inspect raw request)
     73 --field url                    # Replace default payload column with a selected field
     74 ```
     75 
     76 ## Useful advanced switches
     77 
     78 ```bash
     79 -R 1            # Recursive path discovery depth
     80 -L              # Follow HTTP redirections
     81 -Z              # Scan mode: don't abort on connection/DNS errors (errors become XXX)
     82 -m zip          # Pair payloads 1:1 instead of using the default cartesian product
     83 -m chain        # Use one payload after another
     84 -V allvars      # Fuzz all GET params without placing FUZZ in the URL
     85 -V allpost      # Fuzz all POST params without placing FUZZ in the body
     86 --dump-recipe /tmp/wfuzz.rcp  # Save a run for later reuse
     87 --recipe /tmp/wfuzz.rcp       # Re-run a saved recipe
     88 --ip 10.10.10.10              # Connect to a chosen IP while keeping the URL host
     89 ```
     90 
     91 ### Encoders options
     92 
     93 ```bash
     94 wfuzz -e encoders # Prints the available encoders
     95 # Examples: urlencode, md5, base64, hexlify, uri_hex, double urlencode
     96 ```
     97 
     98 In order to use an encoder, you have to indicate it in the **`-w`** or **`-z`** option.<sup>[[2]](#references)</sup>
     99 
    100 Examples:
    101 
    102 ```bash
    103 -z file,/path/to/file,md5 # Will use a list inside the file, and will transform each value into its md5 hash before sending it
    104 -w /path/to/file,base64   # Will use a list, and transform to base64
    105 -z list,each-element-here,hexlify # Inline list and to hex before sending values
    106 ```
    107 
    108 You can also **chain** encoders and **combine payloads**:
    109 
    110 ```bash
    111 # Apply several encoders to the same payload source
    112 wfuzz -z list,1-2-3,sha1-sha1@none http://example.com/FUZZ
    113 
    114 # Pair usernames and passwords line-by-line instead of trying the full cartesian product
    115 wfuzz -w users.txt -w passwords.txt -m zip \
    116   -d 'username=FUZZ&password=FUZ2Z' http://example.com/login
    117 ```
    118 
    119 ## CheatSheet
    120 
    121 ### Login Form bruteforce
    122 
    123 #### **POST, Single list, filter string (hide)**
    124 
    125 ```bash
    126 wfuzz -c -w users.txt --hs "Login name" -d "name=FUZZ&password=FUZZ&autologin=1&enter=Sign+in" http://zipper.htb/zabbix/index.php
    127 # Here we have filtered by regex in the response body
    128 ```
    129 
    130 #### **POST, 2 lists, filter code (show)**
    131 
    132 ```bash
    133 wfuzz.py -c -z file,users.txt -z file,pass.txt --sc 200 -d "name=FUZZ&password=FUZ2Z&autologin=1&enter=Sign+in" http://zipper.htb/zabbix/index.php
    134 # Here we have filtered by code
    135 ```
    136 
    137 #### **POST, 2 paired lists (`zip` iterator)**
    138 
    139 ```bash
    140 wfuzz -c -w users.txt -w passwords.txt -m zip --sc 200 \
    141   -d 'username=FUZZ&password=FUZ2Z' http://example.com/login
    142 ```
    143 
    144 #### **GET, 2 lists, filter string (show), proxy, cookies**
    145 
    146 ```bash
    147 wfuzz -c -w users.txt -w pass.txt --ss "Welcome " -p 127.0.0.1:8080:HTTP -b "PHPSESSIONID=1234567890abcdef;customcookie=hey" "http://example.com/index.php?username=FUZZ&password=FUZ2Z&action=sign+in"
    148 ```
    149 
    150 #### **JSON API login / OTP bruteforce**
    151 
    152 ```bash
    153 wfuzz -c -z range,000000-999999 --hh BBB \
    154   -H 'Content-Type: application/json' \
    155   -d '{"username":"admin","otp":"FUZZ"}' \
    156   http://example.com/api/verify
    157 ```
    158 
    159 ### Bruteforce Directory/RESTful bruteforce
    160 
    161 [Arjun parameters wordlist](https://raw.githubusercontent.com/s0md3v/Arjun/master/arjun/db/params.txt)
    162 
    163 ```bash
    164 wfuzz -c -w /tmp/tmp/params.txt --hc 404 https://domain.com/api/FUZZ
    165 ```
    166 
    167 ### Path Parameters BF
    168 
    169 ```bash
    170 wfuzz -c -w ~/git/Arjun/db/params.txt --hw 11 'http://example.com/path%3BFUZZ=FUZZ'
    171 ```
    172 
    173 ### Fuzz all parameters automatically
    174 
    175 ```bash
    176 # Bruteforce every GET parameter value without placing FUZZ manually
    177 wfuzz -c -z file,/usr/share/seclists/Fuzzing/LFI/LFI-Jhaddix.txt \
    178   -V allvars --hc 404 'http://example.com/index.php?file=1&page=2&lang=en'
    179 
    180 # Same idea for POST bodies
    181 wfuzz -c -z list,"1'-2'-3'" -V allpost \
    182   -d 'username=admin&password=test&otp=000000' \
    183   --ss 'SQL|syntax|warning' http://example.com/login
    184 ```
    185 
    186 ### Header Authentication
    187 
    188 #### **Basic, 2 lists, filter string (show), proxy**
    189 
    190 ```bash
    191 wfuzz -c -w users.txt -w pass.txt -p 127.0.0.1:8080:HTTP --ss "Welcome" --basic FUZZ:FUZ2Z "http://example.com/index.php"
    192 ```
    193 
    194 #### **NTLM, 2 lists, filter string (show), proxy**
    195 
    196 ```bash
    197 wfuzz -c -w users.txt -w pass.txt -p 127.0.0.1:8080:HTTP --ss "Welcome" --ntlm 'domain\FUZZ:FUZ2Z' "http://example.com/index.php"
    198 ```
    199 
    200 ### Cookie/Header bruteforce (vhost brute)
    201 
    202 #### **Cookie, filter code (show), proxy**
    203 
    204 ```bash
    205 wfuzz -c -w users.txt -p 127.0.0.1:8080:HTTP --ss "Welcome " -H "Cookie:id=1312321&user=FUZZ"  "http://example.com/index.php"
    206 ```
    207 
    208 #### **User-Agent, filter code (hide), proxy**
    209 
    210 ```bash
    211 wfuzz -c -w user-agents.txt -p 127.0.0.1:8080:HTTP --ss "Welcome " -H "User-Agent: FUZZ"  "http://example.com/index.php"
    212 ```
    213 
    214 #### **Host**
    215 
    216 ```bash
    217 wfuzz -c -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-20000.txt \
    218   --hc 400,404,403 -H 'Host: FUZZ.example.com' -u http://example.com -t 100
    219 ```
    220 
    221 #### **Host + explicit IP (reverse proxy / misrouting checks)**
    222 
    223 ```bash
    224 wfuzz -c -w vhosts.txt --ip 10.10.10.10 \
    225   --hc BBB -H 'Host: FUZZ.example.com' http://example.com/
    226 ```
    227 
    228 For more methodology around wildcard vhosts and related recon edge-cases, check [this page](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/external-recon-methodology/README.md).
    229 
    230 ### HTTP Verbs (methods) bruteforce
    231 
    232 #### **Using file**
    233 
    234 ```bash
    235 wfuzz -c -w methods.txt -p 127.0.0.1:8080:HTTP --sc 200 -X FUZZ "http://example.com/index.php"
    236 ```
    237 
    238 #### **Using inline list**
    239 
    240 ```bash
    241 wfuzz -z list,GET-HEAD-POST-TRACE-OPTIONS -X FUZZ http://testphp.vulnweb.com/
    242 ```
    243 
    244 ### Directory & Files Bruteforce
    245 
    246 ```bash
    247 # Filter by whitelisting codes
    248 wfuzz -c -z file,/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt --sc 200,202,204,301,302,307,403 http://example.com/uploads/FUZZ
    249 ```
    250 
    251 ### Recursive discovery
    252 
    253 ```bash
    254 # Reuse the same payload inside discovered directories up to depth 2
    255 wfuzz -c -w /usr/share/seclists/Discovery/Web-Content/common.txt \
    256   -R 2 --sc 200,301,302,307,403 http://example.com/FUZZ
    257 ```
    258 
    259 ### Save / restore long fuzzing sessions
    260 
    261 ```bash
    262 wfuzz -c -w dirs.txt --hc 404 --dump-recipe /tmp/wfuzz.recipe http://example.com/FUZZ
    263 wfuzz --recipe /tmp/wfuzz.recipe -b 'session=abc123'
    264 ```
    265 
    266 ## Tool to bypass Webs
    267 
    268 [https://github.com/carlospolop/fuzzhttpbypass](https://github.com/carlospolop/fuzzhttpbypass)
    269 
    270 ## References
    271 
    272 - [1] [Wfuzz - Releases](https://github.com/xmendez/wfuzz/releases)
    273 - [2] [Wfuzz documentation - Advanced usage](https://wfuzz.readthedocs.io/en/latest/user/advanced.html)