ffuf.md (36199B)
1 --- 2 title: "ffuf" 3 description: "ffuf web fuzzing: directory/vhost/parameter discovery, matchers/filters, recursion and wordlists." 4 category: enumeration 5 tags: [enumeration, web, fuzzing] 6 tools: [ffuf] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "vault:Enumeration/ffuf_cheat_sheet.md" 10 --- 11 12 # ffuf 13 14 > **ffuf** — Fast web fuzzer written in Go (v2.1.0+). 15 16 ## Installation 17 18 ```bash 19 # macOS (Homebrew) 20 brew install ffuf 21 22 # Linux (from source) 23 go install github.com/ffuf/ffuf/v2@latest 24 25 # Kali Linux 26 sudo apt install ffuf 27 28 # Docker 29 docker pull ffuf/ffuf 30 docker run --rm ffuf/ffuf -u https://example.com/FUZZ -w /path/to/wordlist 31 ``` 32 33 ## Basic Syntax 34 35 ```bash 36 ffuf [options] -u URL -w WORDLIST 37 ``` 38 39 ### Essential Options 40 41 ```bash 42 -u URL # Target URL (use FUZZ keyword) 43 -w WORDLIST # Wordlist file path 44 -H "Header: value" # Add custom headers 45 -X METHOD # HTTP method (GET, POST, PUT, DELETE, etc.) 46 -d "data" # POST data 47 -t THREADS # Number of concurrent threads (default: 40) 48 -p DELAY # Delay between requests (e.g., 0.1-2.0 seconds) 49 -rate RATE # Rate of requests per second 50 -timeout SECONDS # HTTP request timeout (default: 10) 51 -v # Verbose output 52 -s # Silent mode (no banner) 53 -c # Colorize output 54 -o FILE # Output file 55 -of FORMAT # Output format (json, ejson, html, md, csv, ecsv) 56 -recursion # Enable recursive scanning 57 -recursion-depth N # Maximum recursion depth (default: 0) 58 -e EXTENSIONS # Comma-separated list of extensions to fuzz 59 ``` 60 61 ## Fuzzing Keywords 62 63 ffuf supports multiple fuzzing positions in the same request: 64 65 ```bash 66 FUZZ # Primary fuzzing keyword 67 FUZ2Z # Secondary fuzzing keyword 68 FUZ3Z # Tertiary fuzzing keyword 69 # ... up to FUZ99Z 70 ``` 71 72 ### Examples 73 74 ```bash 75 # Single keyword 76 ffuf -u https://example.com/FUZZ -w wordlist.txt 77 78 # Multiple keywords 79 ffuf -u https://example.com/FUZZ/FUZ2Z -w wordlist1.txt:FUZZ -w wordlist2.txt:FUZ2Z 80 81 # Extension fuzzing 82 ffuf -u https://example.com/file.FUZZ -w extensions.txt 83 ``` 84 85 ## FUZZ Keyword Placement Guide 86 87 This section shows **where** to place the FUZZ keyword to fuzz different parts of requests. 88 89 ### 1. DNS/Subdomain Fuzzing 90 91 ```bash 92 # Subdomain enumeration (DNS FUZZ.website.com) 93 ffuf -u https://FUZZ.example.com -w subdomains.txt 94 95 # Multi-level subdomain fuzzing 96 ffuf -u https://FUZZ.FUZ2Z.example.com \ 97 -w sub1.txt:FUZZ -w sub2.txt:FUZ2Z 98 99 # Real example with common wordlist 100 ffuf -u https://FUZZ.google.com \ 101 -w /opt/SecLists/Discovery/DNS/subdomains-top1million-5000.txt 102 103 # With filtering to remove false positives 104 ffuf -u https://FUZZ.example.com -w subdomains.txt -fs 1234 105 106 # With custom DNS server 107 ffuf -u https://FUZZ.example.com -w subdomains.txt -dns-server 8.8.8.8 108 ``` 109 110 ### 2. URL Path/Directory Fuzzing 111 112 ```bash 113 # Single directory level 114 ffuf -u https://example.com/FUZZ -w directories.txt 115 116 # Nested directory paths 117 ffuf -u https://example.com/api/FUZZ/users -w endpoints.txt 118 119 # Two-level directory fuzzing 120 ffuf -u https://example.com/FUZZ/FUZ2Z \ 121 -w dirs.txt:FUZZ -w subdirs.txt:FUZ2Z 122 123 # Deep path fuzzing 124 ffuf -u https://example.com/app/v1/FUZZ/config -w paths.txt 125 126 # Fuzz entire path 127 ffuf -u https://example.com/FUZZ -w full-paths.txt 128 # Where full-paths.txt contains: admin/login, api/v1/users, etc. 129 ``` 130 131 ### 3. Filename Fuzzing 132 133 ```bash 134 # Fuzz filename only 135 ffuf -u https://example.com/admin/FUZZ.php -w filenames.txt 136 137 # Fuzz filename and extension separately 138 ffuf -u https://example.com/FUZZ.FUZ2Z \ 139 -w filenames.txt:FUZZ -w extensions.txt:FUZ2Z 140 141 # Examples with filenames and extensions 142 ffuf -u https://example.com/FUZZ.FUZ2Z \ 143 -w <(echo -e "index\nadmin\nconfig") \ 144 -w <(echo -e "php\nhtml\nbak\nold") 145 ``` 146 147 ### 4. File Extension Fuzzing 148 149 ```bash 150 # Extension discovery 151 ffuf -u https://example.com/config.FUZZ -w extensions.txt 152 153 # With -e flag for automatic extension appending 154 ffuf -u https://example.com/FUZZ -w files.txt -e .php,.html,.txt,.bak 155 156 # Testing backup file extensions 157 ffuf -u https://example.com/index.php.FUZZ \ 158 -w <(echo -e "bak\nold\n~\nswp\ntmp\nbackup") 159 ``` 160 161 ### 5. GET Parameter Fuzzing 162 163 ```bash 164 # Fuzz parameter NAME 165 ffuf -u "https://example.com/search?FUZZ=value" -w parameters.txt 166 167 # Fuzz parameter VALUE 168 ffuf -u "https://example.com/search?id=FUZZ" -w values.txt 169 170 # Fuzz multiple parameters 171 ffuf -u "https://example.com/api?FUZZ=1&FUZ2Z=2" \ 172 -w params1.txt:FUZZ -w params2.txt:FUZ2Z 173 174 # Fuzz both parameter name AND value 175 ffuf -u "https://example.com?FUZZ=FUZ2Z" \ 176 -w param-names.txt:FUZZ -w param-values.txt:FUZ2Z 177 178 # Multiple existing parameters with one fuzzed 179 ffuf -u "https://example.com/search?user=admin&id=FUZZ&page=1" \ 180 -w ids.txt 181 182 # Testing for hidden parameters 183 ffuf -u "https://example.com/profile?user=john&FUZZ=test" \ 184 -w param-names.txt -fw 100 185 ``` 186 187 ### 6. Virtual Host (VHOST) Header Fuzzing 188 189 ```bash 190 # Basic VHOST fuzzing (subdomain in Host header) 191 ffuf -u http://10.10.10.10 -H "Host: FUZZ.example.com" -w vhosts.txt 192 193 # Fuzz entire hostname 194 ffuf -u http://192.168.1.100 -H "Host: FUZZ" -w hostnames.txt 195 196 # VHOST with port 197 ffuf -u http://example.com -H "Host: FUZZ.example.com:8080" -w vhosts.txt 198 199 # Filter false positives by response size 200 ffuf -u http://10.10.10.10 -H "Host: FUZZ.local" -w vhosts.txt -fs 1234 201 ``` 202 203 ### 7. HTTP Header Fuzzing 204 205 ```bash 206 # Fuzz header VALUE 207 ffuf -u https://example.com -H "X-Custom-Header: FUZZ" -w values.txt 208 209 # Fuzz header NAME 210 ffuf -u https://example.com -H "FUZZ: testvalue" -w header-names.txt 211 212 # Fuzz User-Agent 213 ffuf -u https://example.com -H "User-Agent: FUZZ" -w user-agents.txt 214 215 # Fuzz X-Forwarded-For (IP spoofing) 216 ffuf -u https://example.com -H "X-Forwarded-For: FUZZ" -w ips.txt 217 218 # Multiple header fuzzing 219 ffuf -u https://example.com \ 220 -H "X-Forwarded-For: FUZZ" \ 221 -H "X-Real-IP: FUZ2Z" \ 222 -w ips.txt:FUZZ -w ips.txt:FUZ2Z 223 224 # Authorization header fuzzing 225 ffuf -u https://example.com/admin -H "Authorization: Bearer FUZZ" \ 226 -w tokens.txt 227 228 # Custom API key header 229 ffuf -u https://api.example.com -H "X-API-Key: FUZZ" -w api-keys.txt 230 ``` 231 232 ### 8. POST Data Fuzzing 233 234 ```bash 235 # Fuzz POST parameter VALUE (form data) 236 ffuf -u https://example.com/login -X POST \ 237 -d "username=admin&password=FUZZ" \ 238 -w passwords.txt \ 239 -H "Content-Type: application/x-www-form-urlencoded" 240 241 # Fuzz POST parameter NAME 242 ffuf -u https://example.com/api -X POST \ 243 -d "FUZZ=testvalue" \ 244 -w param-names.txt \ 245 -H "Content-Type: application/x-www-form-urlencoded" 246 247 # Fuzz both username AND password 248 ffuf -u https://example.com/login -X POST \ 249 -d "username=FUZZ&password=FUZ2Z" \ 250 -w usernames.txt:FUZZ -w passwords.txt:FUZ2Z 251 252 # Fuzz multiple POST fields 253 ffuf -u https://example.com/register -X POST \ 254 -d "email=FUZZ@example.com&username=FUZ2Z&role=FUZ3Z" \ 255 -w emails.txt:FUZZ -w users.txt:FUZ2Z -w roles.txt:FUZ3Z 256 ``` 257 258 ### 9. JSON Data Fuzzing 259 260 ```bash 261 # Fuzz JSON field VALUE 262 ffuf -u https://api.example.com/auth -X POST \ 263 -d '{"username":"admin","password":"FUZZ"}' \ 264 -w passwords.txt \ 265 -H "Content-Type: application/json" 266 267 # Fuzz JSON field NAME 268 ffuf -u https://api.example.com/data -X POST \ 269 -d '{"FUZZ":"value"}' \ 270 -w field-names.txt \ 271 -H "Content-Type: application/json" 272 273 # Fuzz nested JSON values 274 ffuf -u https://api.example.com/user -X POST \ 275 -d '{"user":{"name":"admin","role":"FUZZ"}}' \ 276 -w roles.txt \ 277 -H "Content-Type: application/json" 278 279 # Fuzz array elements in JSON 280 ffuf -u https://api.example.com/permissions -X POST \ 281 -d '{"permissions":["read","FUZZ"]}' \ 282 -w permissions.txt \ 283 -H "Content-Type: application/json" 284 ``` 285 286 ### 10. Cookie Fuzzing 287 288 ```bash 289 # Fuzz cookie VALUE 290 ffuf -u https://example.com -b "session=FUZZ" -w sessions.txt 291 292 # Fuzz cookie NAME 293 ffuf -u https://example.com -b "FUZZ=value123" -w cookie-names.txt 294 295 # Multiple cookies with one fuzzed 296 ffuf -u https://example.com -b "session=abc123; token=FUZZ; user=john" \ 297 -w tokens.txt 298 299 # Fuzz multiple cookies simultaneously 300 ffuf -u https://example.com -b "session=FUZZ; userid=FUZ2Z" \ 301 -w sessions.txt:FUZZ -w userids.txt:FUZ2Z 302 303 # Using -H header instead of -b 304 ffuf -u https://example.com \ 305 -H "Cookie: session=FUZZ; token=xyz" \ 306 -w sessions.txt 307 ``` 308 309 ### 11. Protocol & Port Fuzzing 310 311 ```bash 312 # Fuzz protocol (http vs https) 313 ffuf -u FUZZ://api.example.com -w <(echo -e "http\nhttps") 314 315 # Fuzz port numbers 316 ffuf -u https://example.com:FUZZ -w ports.txt 317 # Where ports.txt: 80, 443, 8080, 8443, 3000, 8000, etc. 318 319 # Fuzz subdomain and port together 320 ffuf -u https://FUZZ.example.com:FUZ2Z \ 321 -w subdomains.txt:FUZZ -w ports.txt:FUZ2Z 322 ``` 323 324 ### 12. Username in URL Path 325 326 ```bash 327 # Fuzz username/userid in path 328 ffuf -u https://example.com/users/FUZZ -w usernames.txt 329 330 # Fuzz numeric user IDs 331 seq 1 1000 | ffuf -u https://example.com/profile/FUZZ -w - 332 333 # Fuzz UUID format IDs 334 ffuf -u https://api.example.com/document/FUZZ -w uuids.txt 335 ``` 336 337 ### 13. Fragment/Anchor Fuzzing 338 339 ```bash 340 # Fuzz URL fragment (after #) 341 ffuf -u https://example.com/page#FUZZ -w fragments.txt 342 # Note: Fragments are typically client-side, but can reveal info 343 ``` 344 345 ### 14. File Upload Parameter Fuzzing 346 347 ```bash 348 # Fuzz file upload field name 349 ffuf -u https://example.com/upload -X POST \ 350 -F "FUZZ=@/path/to/file.txt" \ 351 -w field-names.txt 352 353 # Fuzz file content type 354 ffuf -u https://example.com/upload -X POST \ 355 -F "file=@test.txt;type=FUZZ" \ 356 -w content-types.txt 357 ``` 358 359 ### 15. Authentication Fuzzing 360 361 ```bash 362 # Basic Auth username fuzzing 363 echo -n "FUZZ:password" | base64 | \ 364 ffuf -u https://example.com -H "Authorization: Basic $(cat -)" -w usernames.txt 365 366 # Bearer token fuzzing 367 ffuf -u https://api.example.com/admin \ 368 -H "Authorization: Bearer FUZZ" \ 369 -w tokens.txt 370 371 # API key in URL parameter 372 ffuf -u "https://api.example.com/data?apikey=FUZZ" -w keys.txt 373 ``` 374 375 ### 16. Query String Injection Points 376 377 ```bash 378 # Fuzz inside existing query value (SQL injection testing) 379 ffuf -u "https://example.com/search?id=1FUZZ" -w sqli-payloads.txt 380 381 # Fuzz before parameter (path confusion) 382 ffuf -u "https://example.com/FUZZ?id=123" -w paths.txt 383 384 # Multiple injection points in same URL 385 ffuf -u "https://example.com/FUZZ?param=FUZ2Z&data=FUZ3Z" \ 386 -w paths.txt:FUZZ -w values.txt:FUZ2Z -w data.txt:FUZ3Z 387 ``` 388 389 ### 17. GraphQL Fuzzing 390 391 ```bash 392 # Fuzz GraphQL query 393 ffuf -u https://api.example.com/graphql -X POST \ 394 -d '{"query":"{ FUZZ { id name } }"}' \ 395 -w graphql-types.txt \ 396 -H "Content-Type: application/json" 397 398 # Fuzz GraphQL field 399 ffuf -u https://api.example.com/graphql -X POST \ 400 -d '{"query":"{ users { FUZZ } }"}' \ 401 -w field-names.txt \ 402 -H "Content-Type: application/json" 403 ``` 404 405 ### 18. REST API Resource Fuzzing 406 407 ```bash 408 # Fuzz API version 409 ffuf -u https://api.example.com/FUZZ/users -w api-versions.txt 410 # Where api-versions.txt: v1, v2, v3, api/v1, etc. 411 412 # Fuzz API resource type 413 ffuf -u https://api.example.com/api/v1/FUZZ -w resources.txt 414 # Where resources.txt: users, posts, comments, products, etc. 415 416 # Fuzz resource ID 417 ffuf -u https://api.example.com/api/v1/users/FUZZ -w ids.txt 418 ``` 419 420 ### 19. Advanced Multi-Position Fuzzing 421 422 ```bash 423 # Clusterbomb mode - ALL combinations (file.ext) 424 ffuf -mode clusterbomb \ 425 -u https://example.com/FUZZ.FUZ2Z \ 426 -w filenames.txt:FUZZ \ 427 -w extensions.txt:FUZ2Z 428 429 # Pitchfork mode - Parallel iteration (line by line) 430 ffuf -mode pitchfork \ 431 -u https://example.com/FUZZ \ 432 -w urls.txt:FUZZ \ 433 -w specific-values.txt:FUZ2Z 434 435 # Three fuzzing positions 436 ffuf -u https://FUZZ.example.com/FUZ2Z/FUZ3Z \ 437 -w subdomains.txt:FUZZ \ 438 -w dirs.txt:FUZ2Z \ 439 -w files.txt:FUZ3Z 440 ``` 441 442 ### 20. Special Characters & Encoding 443 444 ```bash 445 # URL-encoded fuzzing 446 ffuf -u "https://example.com/search?q=FUZZ" -w encoded-payloads.txt 447 448 # Double URL encoding 449 ffuf -u "https://example.com/path/FUZZ" -w double-encoded.txt 450 451 # Base64 encoded values 452 ffuf -u https://example.com/data/FUZZ -w base64-values.txt 453 454 # Fuzz with special characters (testing WAF bypass) 455 ffuf -u "https://example.com/FUZZ" -w special-chars.txt 456 ``` 457 458 ### FUZZ Placement Quick Reference Table 459 460 | Target | Example | Wordlist Type | 461 |--------|---------|---------------| 462 | **Subdomain** | `https://FUZZ.example.com` | subdomains.txt | 463 | **Directory** | `https://example.com/FUZZ` | directories.txt | 464 | **File** | `https://example.com/admin/FUZZ.php` | filenames.txt | 465 | **Extension** | `https://example.com/config.FUZZ` | extensions.txt | 466 | **GET Param Name** | `https://example.com?FUZZ=value` | parameters.txt | 467 | **GET Param Value** | `https://example.com?id=FUZZ` | values.txt | 468 | **POST Data** | `-d "user=admin&pass=FUZZ"` | passwords.txt | 469 | **JSON Value** | `-d '{"user":"FUZZ"}'` | usernames.txt | 470 | **Header Value** | `-H "X-Auth: FUZZ"` | tokens.txt | 471 | **Cookie Value** | `-b "session=FUZZ"` | sessions.txt | 472 | **VHOST** | `-H "Host: FUZZ.local"` | vhosts.txt | 473 | **Port** | `https://example.com:FUZZ` | ports.txt | 474 | **User ID** | `https://site.com/user/FUZZ` | userids.txt | 475 476 ## Common Use Cases 477 478 ### 1. Directory & File Fuzzing 479 480 ```bash 481 # Basic directory enumeration 482 ffuf -u https://example.com/FUZZ -w /usr/share/wordlists/dirb/common.txt 483 484 # Directory fuzzing with extensions 485 ffuf -u https://example.com/FUZZ -w wordlist.txt -e .php,.html,.txt,.bak 486 487 # File extension enumeration 488 ffuf -u https://example.com/admin.FUZZ -w extensions.txt 489 490 # Recursive directory scanning 491 ffuf -u https://example.com/FUZZ -w wordlist.txt -recursion -recursion-depth 2 492 493 # Only show 200 responses 494 ffuf -u https://example.com/FUZZ -w wordlist.txt -mc 200 495 ``` 496 497 ### 2. Subdomain Enumeration 498 499 ```bash 500 # Basic subdomain fuzzing 501 ffuf -u https://FUZZ.example.com -w subdomains.txt 502 503 # With custom DNS server 504 ffuf -u https://FUZZ.example.com -w subdomains.txt -dns-server 8.8.8.8 505 506 # Filtering by response size 507 ffuf -u https://FUZZ.example.com -w subdomains.txt -fs 4242 508 ``` 509 510 ### 3. Virtual Host Discovery 511 512 ```bash 513 # VHOST enumeration 514 ffuf -u https://example.com -H "Host: FUZZ.example.com" -w wordlist.txt 515 516 # Filter false positives by size 517 ffuf -u https://10.10.10.10 -H "Host: FUZZ.example.local" -w wordlist.txt -fs 1234 518 519 # Multiple header fuzzing 520 ffuf -u https://example.com -H "Host: FUZZ" -H "X-Forwarded-For: FUZ2Z" \ 521 -w vhosts.txt:FUZZ -w ips.txt:FUZ2Z 522 ``` 523 524 ### 4. Parameter Fuzzing (GET) 525 526 ```bash 527 # GET parameter discovery 528 ffuf -u https://example.com?FUZZ=test -w params.txt 529 530 # Multiple parameters 531 ffuf -u https://example.com?FUZZ=FUZ2Z -w params.txt:FUZZ -w values.txt:FUZ2Z 532 533 # Parameter value fuzzing 534 ffuf -u https://example.com?id=FUZZ -w numbers.txt 535 536 # Filter by response size 537 ffuf -u https://example.com?page=FUZZ -w wordlist.txt -fs 0 538 ``` 539 540 ### 5. POST Data Fuzzing 541 542 ```bash 543 # POST parameter fuzzing 544 ffuf -u https://example.com/login -X POST -d "username=admin&password=FUZZ" \ 545 -w passwords.txt -H "Content-Type: application/x-www-form-urlencoded" 546 547 # JSON POST fuzzing 548 ffuf -u https://example.com/api -X POST \ 549 -d '{"username":"admin","password":"FUZZ"}' \ 550 -w passwords.txt -H "Content-Type: application/json" 551 552 # Username and password fuzzing 553 ffuf -u https://example.com/login -X POST \ 554 -d "username=FUZZ&password=FUZ2Z" \ 555 -w usernames.txt:FUZZ -w passwords.txt:FUZ2Z 556 ``` 557 558 ### 6. API Endpoint Fuzzing 559 560 ```bash 561 # API endpoint discovery 562 ffuf -u https://api.example.com/v1/FUZZ -w api-endpoints.txt 563 564 # API version fuzzing 565 ffuf -u https://api.example.com/FUZZ/users -w versions.txt 566 567 # RESTful API fuzzing 568 ffuf -u https://api.example.com/api/FUZZ -w wordlist.txt \ 569 -H "Authorization: Bearer TOKEN" 570 ``` 571 572 ### 7. Username Enumeration 573 574 ```bash 575 # Login form username enumeration 576 ffuf -u https://example.com/login -X POST \ 577 -d "username=FUZZ&password=invalid" \ 578 -w usernames.txt -mr "Invalid password" 579 580 # User profile enumeration 581 ffuf -u https://example.com/users/FUZZ -w usernames.txt -mc 200 582 583 # Email enumeration 584 ffuf -u https://example.com/forgot-password -X POST \ 585 -d "email=FUZZ@example.com" -w wordlist.txt -mr "sent" 586 ``` 587 588 ### 8. File Backup Enumeration 589 590 ```bash 591 # Common backup extensions 592 ffuf -u https://example.com/admin.FUZZ -w backup-extensions.txt 593 594 # Backup file patterns 595 ffuf -u https://example.com/FUZZ -w backup-patterns.txt 596 # Where backup-patterns.txt contains: index.php.bak, index.php~, index.php.old, etc. 597 598 # Combined filename and extension fuzzing 599 ffuf -u https://example.com/FUZZ.FUZ2Z \ 600 -w filenames.txt:FUZZ -w extensions.txt:FUZ2Z 601 ``` 602 603 ## Filter Options 604 605 Filters HIDE matching responses (exclude from results): 606 607 ```bash 608 -fc CODE1,CODE2 # Filter HTTP status codes 609 -fs SIZE1,SIZE2 # Filter response size (bytes) 610 -fw WORDS1,WORDS2 # Filter word count 611 -fl LINES1,LINES2 # Filter line count 612 -fr REGEX # Filter responses matching regex 613 -ft TIME # Filter response time (milliseconds) 614 ``` 615 616 ### Filter Examples 617 618 ```bash 619 # Hide 404 and 403 responses 620 ffuf -u https://example.com/FUZZ -w wordlist.txt -fc 404,403 621 622 # Hide responses of specific size 623 ffuf -u https://example.com/FUZZ -w wordlist.txt -fs 4242 624 625 # Hide responses with specific word count 626 ffuf -u https://FUZZ.example.com -w subdomains.txt -fw 1337 627 628 # Hide responses matching "Not Found" 629 ffuf -u https://example.com/FUZZ -w wordlist.txt -fr "Not Found" 630 631 # Combine multiple filters 632 ffuf -u https://example.com/FUZZ -w wordlist.txt -fc 404,403 -fs 0 -fw 1 633 ``` 634 635 ## Matcher Options 636 637 Matchers SHOW matching responses (include in results): 638 639 ```bash 640 -mc CODE1,CODE2 # Match HTTP status codes 641 -ms SIZE1,SIZE2 # Match response size (bytes) 642 -mw WORDS1,WORDS2 # Match word count 643 -ml LINES1,LINES2 # Match line count 644 -mr REGEX # Match responses containing regex 645 -mt TIME # Match response time (milliseconds) 646 ``` 647 648 ### Matcher Examples 649 650 ```bash 651 # Only show 200 and 301 responses 652 ffuf -u https://example.com/FUZZ -w wordlist.txt -mc 200,301 653 654 # Match specific response size 655 ffuf -u https://example.com/FUZZ -w wordlist.txt -ms 1337 656 657 # Match responses containing "success" 658 ffuf -u https://example.com/login -X POST -d "user=admin&pass=FUZZ" \ 659 -w passwords.txt -mr "success" 660 661 # Match slow responses (potential SQL injection) 662 ffuf -u https://example.com/search?q=FUZZ -w sqli-payloads.txt -mt ">3000" 663 664 # Combine matchers 665 ffuf -u https://example.com/FUZZ -w wordlist.txt -mc 200 -ms 1000-5000 666 ``` 667 668 ## Rate Limiting & Performance 669 670 ```bash 671 # Set number of threads (default: 40) 672 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 100 673 674 # Rate limiting (requests per second) 675 ffuf -u https://example.com/FUZZ -w wordlist.txt -rate 10 676 677 # Add delay between requests (seconds) 678 ffuf -u https://example.com/FUZZ -w wordlist.txt -p 0.5 679 680 # Set timeout (default: 10s) 681 ffuf -u https://example.com/FUZZ -w wordlist.txt -timeout 30 682 683 # Max execution time (seconds) 684 ffuf -u https://example.com/FUZZ -w wordlist.txt -maxtime 600 685 686 # Stop after errors 687 ffuf -u https://example.com/FUZZ -w wordlist.txt -se 688 ``` 689 690 ### Performance Tips 691 692 ```bash 693 # Fast scan (more threads, higher rate) 694 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 200 -rate 100 695 696 # Stealth scan (slower, less noise) 697 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 5 -rate 2 -p 1 698 699 # Balanced scan 700 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 40 -rate 50 701 ``` 702 703 ## Output Formats 704 705 ```bash 706 # Save output to file 707 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.txt 708 709 # JSON output 710 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.json -of json 711 712 # HTML report 713 ffuf -u https://example.com/FUZZ -w wordlist.txt -o report.html -of html 714 715 # Markdown output 716 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.md -of md 717 718 # CSV output 719 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.csv -of csv 720 721 # eJSON (one JSON per line - easy to parse) 722 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.ejson -of ejson 723 724 # CSV with base64 (includes response body) 725 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.csv -of ecsv 726 ``` 727 728 ### Output Parsing Examples 729 730 ```bash 731 # Parse JSON output with jq 732 cat results.json | jq '.results[] | select(.status == 200) | .url' 733 734 # Extract URLs from eJSON 735 cat results.ejson | jq -r '.url' 736 737 # Filter by status code 738 cat results.ejson | jq -r 'select(.status == 200) | .url' 739 ``` 740 741 ## Authentication 742 743 ### Basic Authentication 744 745 ```bash 746 # Basic auth 747 ffuf -u https://example.com/FUZZ -w wordlist.txt -H "Authorization: Basic dXNlcjpwYXNz" 748 749 # Or use base64 directly 750 echo -n "username:password" | base64 751 ffuf -u https://example.com/FUZZ -w wordlist.txt -H "Authorization: Basic BASE64_HERE" 752 ``` 753 754 ### Bearer Token 755 756 ```bash 757 # JWT/Bearer token 758 ffuf -u https://api.example.com/FUZZ -w wordlist.txt \ 759 -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." 760 ``` 761 762 ### Cookie-Based Authentication 763 764 ```bash 765 # Using cookies 766 ffuf -u https://example.com/FUZZ -w wordlist.txt \ 767 -b "session=abc123; token=xyz789" 768 769 # Or with header 770 ffuf -u https://example.com/FUZZ -w wordlist.txt \ 771 -H "Cookie: session=abc123; token=xyz789" 772 ``` 773 774 ### Custom Authentication Header 775 776 ```bash 777 # API key 778 ffuf -u https://api.example.com/FUZZ -w wordlist.txt \ 779 -H "X-API-Key: your-api-key-here" 780 781 # Multiple auth headers 782 ffuf -u https://example.com/FUZZ -w wordlist.txt \ 783 -H "X-API-Key: key123" \ 784 -H "X-Auth-Token: token456" 785 ``` 786 787 ## HTTP Methods 788 789 ```bash 790 # GET (default) 791 ffuf -u https://example.com/FUZZ -w wordlist.txt 792 793 # POST 794 ffuf -u https://example.com/api/FUZZ -X POST -w wordlist.txt 795 796 # PUT 797 ffuf -u https://example.com/api/users/FUZZ -X PUT \ 798 -d '{"data":"value"}' -w wordlist.txt 799 800 # DELETE 801 ffuf -u https://example.com/api/users/FUZZ -X DELETE -w wordlist.txt 802 803 # HEAD (faster for discovery) 804 ffuf -u https://example.com/FUZZ -X HEAD -w wordlist.txt 805 806 # OPTIONS (enumerate HTTP methods) 807 ffuf -u https://example.com/FUZZ -X OPTIONS -w wordlist.txt 808 809 # PATCH 810 ffuf -u https://example.com/api/users/FUZZ -X PATCH \ 811 -d '{"field":"value"}' -w wordlist.txt 812 ``` 813 814 ## Advanced Techniques 815 816 ### 1. Recursive Scanning 817 818 ```bash 819 # Enable recursion 820 ffuf -u https://example.com/FUZZ -w wordlist.txt -recursion 821 822 # Set recursion depth 823 ffuf -u https://example.com/FUZZ -w wordlist.txt -recursion -recursion-depth 3 824 825 # Recursion with custom strategy 826 ffuf -u https://example.com/FUZZ -w wordlist.txt \ 827 -recursion -recursion-depth 2 -recursion-strategy greedy 828 ``` 829 830 ### 2. Replay Proxy (for Burp Suite/OWASP ZAP) 831 832 ```bash 833 # Send requests through proxy 834 ffuf -u https://example.com/FUZZ -w wordlist.txt \ 835 -replay-proxy http://127.0.0.1:8080 836 837 # With proxy authentication 838 ffuf -u https://example.com/FUZZ -w wordlist.txt \ 839 -replay-proxy http://user:pass@127.0.0.1:8080 840 ``` 841 842 ### 3. Client Certificates 843 844 ```bash 845 # Using client certificate 846 ffuf -u https://example.com/FUZZ -w wordlist.txt \ 847 -cert /path/to/cert.pem -key /path/to/key.pem 848 ``` 849 850 ### 4. Custom SNI 851 852 ```bash 853 # Server Name Indication 854 ffuf -u https://10.10.10.10/FUZZ -w wordlist.txt -sni example.com 855 ``` 856 857 ### 5. Follow Redirects 858 859 ```bash 860 # Follow redirects 861 ffuf -u https://example.com/FUZZ -w wordlist.txt -r 862 863 # Max redirect depth 864 ffuf -u https://example.com/FUZZ -w wordlist.txt -r -maxredirs 5 865 ``` 866 867 ### 6. Auto-Calibration 868 869 ```bash 870 # Auto-calibrate filters (removes false positives) 871 ffuf -u https://example.com/FUZZ -w wordlist.txt -ac 872 873 # Auto-calibration with custom strategy 874 ffuf -u https://example.com/FUZZ -w wordlist.txt -ac -acc 95 875 ``` 876 877 ### 7. Request/Response Inspection 878 879 ```bash 880 # Show request/response for debugging 881 ffuf -u https://example.com/FUZZ -w wordlist.txt -v 882 883 # Show only specific status codes in verbose 884 ffuf -u https://example.com/FUZZ -w wordlist.txt -mc 200 -v 885 ``` 886 887 ### 8. Custom User-Agent 888 889 ```bash 890 # Custom User-Agent 891 ffuf -u https://example.com/FUZZ -w wordlist.txt \ 892 -H "User-Agent: Mozilla/5.0 (custom)" 893 894 # Random User-Agent per request (requires UA wordlist) 895 ffuf -u https://example.com/FUZZ -w dirs.txt:FUZZ -w user-agents.txt:USERAGENT \ 896 -H "User-Agent: USERAGENT" 897 ``` 898 899 ### 9. Input Modes 900 901 ```bash 902 # Clusterbomb mode (cartesian product) 903 ffuf -mode clusterbomb -u https://example.com/FUZZ/FUZ2Z \ 904 -w wordlist1.txt:FUZZ -w wordlist2.txt:FUZ2Z 905 906 # Pitchfork mode (parallel iteration) 907 ffuf -mode pitchfork -u https://example.com/FUZZ \ 908 -w wordlist1.txt:FUZZ -w wordlist2.txt:FUZ2Z 909 ``` 910 911 ### 10. Input from stdin 912 913 ```bash 914 # Use stdin as wordlist 915 cat wordlist.txt | ffuf -u https://example.com/FUZZ -w - 916 917 # Combine with other tools 918 cat targets.txt | httpx -silent | ffuf -u FUZZ/admin -w - 919 ``` 920 921 ## Common Wordlists 922 923 ### SecLists (Recommended) 924 925 ```bash 926 # Install SecLists 927 git clone https://github.com/danielmiessler/SecLists.git /opt/SecLists 928 ``` 929 930 ### Directory & File Discovery 931 932 ```text 933 /usr/share/wordlists/dirb/common.txt 934 /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt 935 /opt/SecLists/Discovery/Web-Content/directory-list-2.3-medium.txt 936 /opt/SecLists/Discovery/Web-Content/raft-large-directories.txt 937 /opt/SecLists/Discovery/Web-Content/big.txt 938 /opt/SecLists/Discovery/Web-Content/common.txt 939 ``` 940 941 ### Subdomains 942 943 ```text 944 /opt/SecLists/Discovery/DNS/subdomains-top1million-5000.txt 945 /opt/SecLists/Discovery/DNS/subdomains-top1million-20000.txt 946 /opt/SecLists/Discovery/DNS/subdomains-top1million-110000.txt 947 /opt/SecLists/Discovery/DNS/bitquark-subdomains-top100000.txt 948 ``` 949 950 ### Parameters 951 952 ```text 953 /opt/SecLists/Discovery/Web-Content/burp-parameter-names.txt 954 /opt/SecLists/Discovery/Web-Content/api/api-endpoints.txt 955 /opt/SecLists/Discovery/Web-Content/common-api-endpoints-mazen160.txt 956 ``` 957 958 ### Usernames 959 960 ```text 961 /opt/SecLists/Usernames/Names/names.txt 962 /opt/SecLists/Usernames/top-usernames-shortlist.txt 963 /opt/SecLists/Usernames/xato-net-10-million-usernames.txt 964 ``` 965 966 ### Passwords 967 968 ```text 969 /usr/share/wordlists/rockyou.txt 970 /opt/SecLists/Passwords/Common-Credentials/10-million-password-list-top-1000000.txt 971 /opt/SecLists/Passwords/darkweb2017-top10000.txt 972 ``` 973 974 ### Extensions 975 976 ```bash 977 # Create custom extension list 978 echo -e ".php\n.html\n.js\n.json\n.xml\n.bak\n.old\n.txt\n.asp\n.aspx\n.jsp" > extensions.txt 979 ``` 980 981 ## Tips & Tricks 982 983 ### 1. Finding the Right Filters 984 985 ```bash 986 # First run without filters to see baseline 987 ffuf -u https://example.com/FUZZ -w wordlist.txt 988 989 # Then add filters based on false positive patterns 990 ffuf -u https://example.com/FUZZ -w wordlist.txt -fs 4242 -fw 337 991 992 # Use auto-calibration 993 ffuf -u https://example.com/FUZZ -w wordlist.txt -ac 994 ``` 995 996 ### 2. Speed Optimization 997 998 ```bash 999 # Use HEAD method for faster discovery 1000 ffuf -u https://example.com/FUZZ -w wordlist.txt -X HEAD 1001 1002 # Increase threads for faster scanning 1003 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 100 1004 1005 # Use smaller wordlists first 1006 ffuf -u https://example.com/FUZZ -w common.txt -t 50 1007 ``` 1008 1009 ### 3. Stealth & Evasion 1010 1011 ```bash 1012 # Slow and steady 1013 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 5 -p 2 -rate 1 1014 1015 # Randomize User-Agent 1016 ffuf -u https://example.com/FUZZ -w dirs.txt:FUZZ -w ua.txt:UA \ 1017 -H "User-Agent: UA" -mode pitchfork 1018 1019 # Add random delay 1020 ffuf -u https://example.com/FUZZ -w wordlist.txt -p 0.5-2.0 1021 ``` 1022 1023 ### 4. Finding Hidden Parameters 1024 1025 ```bash 1026 # GET parameter discovery with value testing 1027 ffuf -u "https://example.com?FUZZ=test" -w params.txt -fw 100 1028 1029 # POST parameter discovery 1030 ffuf -u https://example.com/search -X POST \ 1031 -d "FUZZ=test" -w params.txt -H "Content-Type: application/x-www-form-urlencoded" 1032 1033 # JSON parameter discovery 1034 ffuf -u https://api.example.com/endpoint -X POST \ 1035 -d '{"FUZZ":"test"}' -w params.txt -H "Content-Type: application/json" 1036 ``` 1037 1038 ### 5. Combining with Other Tools 1039 1040 ```bash 1041 # Chain with subfinder 1042 subfinder -d example.com -silent | ffuf -u https://FUZZ/admin -w - 1043 1044 # Chain with waybackurls 1045 waybackurls example.com | grep -E "\.(js|php|asp)" | ffuf -u FUZZ -w - 1046 1047 # Pipe to httpx for validation 1048 ffuf -u https://example.com/FUZZ -w wordlist.txt -mc 200 -o urls.txt -of csv | \ 1049 awk -F, '{print $1}' | httpx -silent 1050 ``` 1051 1052 ### 6. Pattern-Based Fuzzing 1053 1054 ```bash 1055 # Numeric ID fuzzing 1056 seq 1 1000 | ffuf -u https://example.com/user/FUZZ -w - 1057 1058 # Date-based fuzzing 1059 for year in {2020..2024}; do 1060 for month in {01..12}; do 1061 echo "$year-$month" 1062 done 1063 done | ffuf -u https://example.com/archive/FUZZ -w - 1064 1065 # Hex ID fuzzing 1066 for i in {0..255}; do printf "%02x\n" $i; done | ffuf -u https://example.com/id/FUZZ -w - 1067 ``` 1068 1069 ### 7. Response Size Ranges 1070 1071 ```bash 1072 # Match response size ranges 1073 ffuf -u https://example.com/FUZZ -w wordlist.txt -ms 1000-5000 1074 1075 # Filter size ranges 1076 ffuf -u https://example.com/FUZZ -w wordlist.txt -fs 0-100 1077 ``` 1078 1079 ### 8. Content-Type Fuzzing 1080 1081 ```bash 1082 # Fuzz Content-Type header 1083 ffuf -u https://example.com/upload -X POST \ 1084 -d "data" -H "Content-Type: FUZZ" -w content-types.txt 1085 # content-types.txt: application/json, application/xml, text/plain, multipart/form-data 1086 ``` 1087 1088 ### 9. Debugging Failed Scans 1089 1090 ```bash 1091 # Verbose output with request/response 1092 ffuf -u https://example.com/FUZZ -w wordlist.txt -v 1093 1094 # Test with single word first 1095 echo "test" | ffuf -u https://example.com/FUZZ -w - -v 1096 1097 # Check DNS resolution 1098 ffuf -u https://FUZZ.example.com -w subdomain.txt -debug-log debug.log 1099 ``` 1100 1101 ### 10. Multiple Wordlist Strategies 1102 1103 ```bash 1104 # Clusterbomb (all combinations) 1105 ffuf -mode clusterbomb -u https://example.com/FUZZ.FUZ2Z \ 1106 -w files.txt:FUZZ -w extensions.txt:FUZ2Z 1107 1108 # Pitchfork (parallel - line by line) 1109 ffuf -mode pitchfork -u https://example.com/FUZZ \ 1110 -w wordlist1.txt:FUZZ -w wordlist2.txt:FUZ2Z 1111 ``` 1112 1113 ## Real-World Examples 1114 1115 ### Example 1: Complete Web App Enumeration 1116 1117 ```bash 1118 # Step 1: Find directories 1119 ffuf -u https://target.com/FUZZ -w common.txt -mc 200,301,302,401,403 -o dirs.json -of json 1120 1121 # Step 2: Find files in discovered directories 1122 ffuf -u https://target.com/admin/FUZZ -w files.txt -e .php,.html,.txt,.bak -mc 200 1123 1124 # Step 3: Parameter discovery 1125 ffuf -u "https://target.com/search?FUZZ=test" -w params.txt -fw 100 1126 1127 # Step 4: Virtual host discovery 1128 ffuf -u https://target.com -H "Host: FUZZ.target.com" -w vhosts.txt -fs 4242 1129 ``` 1130 1131 ### Example 2: API Endpoint Discovery 1132 1133 ```bash 1134 # Find API endpoints 1135 ffuf -u https://api.target.com/v1/FUZZ -w api-endpoints.txt -mc 200,401,403 1136 1137 # Test different API versions 1138 ffuf -u https://api.target.com/FUZZ/users -w api-versions.txt 1139 1140 # Find API objects 1141 ffuf -u https://api.target.com/api/v1/FUZZ -w api-objects.txt -H "Authorization: Bearer TOKEN" 1142 1143 # Numeric ID enumeration 1144 seq 1 10000 | ffuf -u https://api.target.com/api/v1/users/FUZZ -w - -mc 200 1145 ``` 1146 1147 ### Example 3: Subdomain Takeover Check 1148 1149 ```bash 1150 # Find subdomains 1151 ffuf -u https://FUZZ.target.com -w subdomains.txt -mc 200,301,302 -o subdomains.txt -of csv 1152 1153 # Check for CNAME records 1154 cat subdomains.txt | awk -F, '{print $1}' | while read sub; do 1155 dig +short $sub CNAME 1156 done 1157 1158 # Check for common takeover patterns 1159 ffuf -u https://FUZZ.target.com -w discovered-subs.txt -mr "NoSuchBucket|Repository not found|404" 1160 ``` 1161 1162 ### Example 4: IDOR Testing 1163 1164 ```bash 1165 # Enumerate user IDs 1166 seq 1 1000 | ffuf -u https://target.com/api/user/FUZZ -w - \ 1167 -H "Authorization: Bearer YOUR_TOKEN" -mc 200 1168 1169 # Test UUID format 1170 cat uuids.txt | ffuf -u https://target.com/api/document/FUZZ -w - \ 1171 -H "Cookie: session=xyz" -mc 200 -v 1172 ``` 1173 1174 ### Example 5: SQLi & XSS Parameter Fuzzing 1175 1176 ```bash 1177 # Find injectable parameters (SQL injection) 1178 ffuf -u "https://target.com/search?id=FUZZ" -w sqli-payloads.txt \ 1179 -mr "SQL syntax|mysql_fetch|error in your SQL" -v 1180 1181 # XSS parameter fuzzing 1182 ffuf -u "https://target.com/search?q=FUZZ" -w xss-payloads.txt \ 1183 -mr "<script>|alert\(1\)" -v 1184 1185 # Slow response detection (time-based SQLi) 1186 ffuf -u "https://target.com/search?id=FUZZ" -w time-sqli.txt -mt ">3000" 1187 ``` 1188 1189 ### Example 6: WordPress Scanning 1190 1191 ```bash 1192 # Find WordPress plugins 1193 ffuf -u https://target.com/wp-content/plugins/FUZZ/readme.txt -w wp-plugins.txt -mc 200 1194 1195 # Find WordPress themes 1196 ffuf -u https://target.com/wp-content/themes/FUZZ/style.css -w wp-themes.txt -mc 200 1197 1198 # Find WordPress users 1199 seq 1 100 | ffuf -u https://target.com/?author=FUZZ -w - -fc 404 1200 1201 # WordPress xmlrpc brute force 1202 ffuf -u https://target.com/xmlrpc.php -X POST \ 1203 -d '<methodCall><methodName>wp.getUsersBlogs</methodName><params><param><value>admin</value></param><param><value>FUZZ</value></param></params></methodCall>' \ 1204 -w passwords.txt -mr "isAdmin" 1205 ``` 1206 1207 ### Example 7: Multi-Stage Fuzzing 1208 1209 ```bash 1210 # Stage 1: Find subdomains 1211 ffuf -u https://FUZZ.target.com -w subdomains.txt -mc 200 -o stage1.json -of json 1212 1213 # Stage 2: Extract live hosts and fuzz paths 1214 cat stage1.json | jq -r '.results[].url' | while read url; do 1215 ffuf -u $url/FUZZ -w paths.txt -mc 200,301,302 1216 done 1217 1218 # Stage 3: Fuzz parameters on discovered endpoints (manual, based on Stage 2) 1219 ``` 1220 1221 ### Example 8: GraphQL Endpoint Enumeration 1222 1223 ```bash 1224 # Find GraphQL endpoint 1225 ffuf -u https://target.com/FUZZ -w graphql-paths.txt -mc 200,400 -mr "graphql|query" 1226 1227 # GraphQL introspection query fuzzing 1228 ffuf -u https://target.com/graphql -X POST \ 1229 -d '{"query":"FUZZ"}' -w graphql-queries.txt \ 1230 -H "Content-Type: application/json" -mc 200 1231 ``` 1232 1233 ### Example 9: Cloud Bucket Discovery 1234 1235 ```bash 1236 # S3 bucket enumeration 1237 ffuf -u https://FUZZ.s3.amazonaws.com -w bucket-names.txt -mc 200,403 1238 1239 # Azure blob storage 1240 ffuf -u https://FUZZ.blob.core.windows.net -w storage-names.txt -mc 200,403 1241 1242 # Google Cloud Storage 1243 ffuf -u https://storage.googleapis.com/FUZZ -w bucket-names.txt -mc 200,403 1244 ``` 1245 1246 ### Example 10: JWT Secret Fuzzing 1247 1248 ```bash 1249 # Fuzz JWT secrets (generate JWTs with FUZZ as secret using a script) 1250 ffuf -u https://target.com/api/admin -X GET \ 1251 -H "Authorization: Bearer JWT_WITH_FUZZ_SECRET" \ 1252 -w jwt-secrets.txt -mc 200 1253 ``` 1254 1255 ## Quick Reference Card 1256 1257 ```bash 1258 # Basic directory fuzzing 1259 ffuf -u https://target.com/FUZZ -w wordlist.txt 1260 1261 # With extensions 1262 ffuf -u https://target.com/FUZZ -w wordlist.txt -e .php,.html,.txt 1263 1264 # Subdomain enumeration 1265 ffuf -u https://FUZZ.target.com -w subdomains.txt 1266 1267 # VHOST fuzzing 1268 ffuf -u https://target.com -H "Host: FUZZ" -w vhosts.txt 1269 1270 # POST data fuzzing 1271 ffuf -u https://target.com/login -X POST -d "user=admin&pass=FUZZ" -w passwords.txt 1272 1273 # Filter by status code 1274 ffuf -u https://target.com/FUZZ -w wordlist.txt -fc 404,403 1275 1276 # Match status code 1277 ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301 1278 1279 # Filter by size 1280 ffuf -u https://target.com/FUZZ -w wordlist.txt -fs 4242 1281 1282 # Save output 1283 ffuf -u https://target.com/FUZZ -w wordlist.txt -o results.json -of json 1284 1285 # Recursive scanning 1286 ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 2 1287 1288 # Rate limiting 1289 ffuf -u https://target.com/FUZZ -w wordlist.txt -rate 10 -t 5 1290 1291 # Through proxy 1292 ffuf -u https://target.com/FUZZ -w wordlist.txt -replay-proxy http://127.0.0.1:8080 1293 1294 # Auto-calibration 1295 ffuf -u https://target.com/FUZZ -w wordlist.txt -ac 1296 ``` 1297 1298 ## Common Errors & Solutions 1299 1300 - **"no wordlist defined"** — Specify a wordlist with `-w`. 1301 - **"no target url defined"** — Specify a URL with `-u`. 1302 - **"no FUZZ keyword found"** — Your URL or data must contain the keyword `FUZZ`. 1303 - **High false positive rate** — Use `-ac` for auto-calibration; add filters (`-fc 404 -fs 0`); use matchers (`-mc 200`). 1304 - **Too slow** — Increase threads (`-t 100`); use smaller wordlist first; use HEAD method (`-X HEAD`). 1305 - **Getting blocked/rate limited** — Reduce threads (`-t 5`); add delay (`-p 1`); reduce rate (`-rate 5`); rotate User-Agent; use a proxy. 1306 - **No results showing** — Remove filters temporarily; check if site is up; use `-v`; check matcher settings. 1307 1308 ## Comparison: ffuf vs wfuzz vs gobuster 1309 1310 | Feature | ffuf | wfuzz | gobuster | 1311 |---------|------|-------|----------| 1312 | Speed | High | Medium | High | 1313 | Ease of Use | High | Medium | High | 1314 | Features | High | High | Medium | 1315 | Recursion | Yes | No | Yes | 1316 | Multiple Keywords | Yes | Yes | No | 1317 | Output Formats | Many | Few | Few | 1318 | Auto-Calibration | Yes | No | No | 1319 1320 ffuf is generally the best all-around choice for modern web fuzzing. 1321 1322 ## Resources 1323 1324 - Official repo: https://github.com/ffuf/ffuf 1325 - Documentation: https://github.com/ffuf/ffuf/wiki 1326 - SecLists: https://github.com/danielmiessler/SecLists 1327 - PayloadsAllTheThings: https://github.com/swisskyrepo/PayloadsAllTheThings 1328 1329 > Always ensure you have proper authorization before testing any target.