daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ffuf.md (36199B)


      1 ---
      2 title: "ffuf"
      3 description: "ffuf web fuzzing: directory/vhost/parameter discovery, matchers/filters, recursion and wordlists."
      4 category: enumeration
      5 tags: [enumeration, web, fuzzing]
      6 tools: [ffuf]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "vault:Enumeration/ffuf_cheat_sheet.md"
     10 ---
     11 
     12 # ffuf
     13 
     14 > **ffuf** — Fast web fuzzer written in Go (v2.1.0+).
     15 
     16 ## Installation
     17 
     18 ```bash
     19 # macOS (Homebrew)
     20 brew install ffuf
     21 
     22 # Linux (from source)
     23 go install github.com/ffuf/ffuf/v2@latest
     24 
     25 # Kali Linux
     26 sudo apt install ffuf
     27 
     28 # Docker
     29 docker pull ffuf/ffuf
     30 docker run --rm ffuf/ffuf -u https://example.com/FUZZ -w /path/to/wordlist
     31 ```
     32 
     33 ## Basic Syntax
     34 
     35 ```bash
     36 ffuf [options] -u URL -w WORDLIST
     37 ```
     38 
     39 ### Essential Options
     40 
     41 ```bash
     42 -u URL              # Target URL (use FUZZ keyword)
     43 -w WORDLIST         # Wordlist file path
     44 -H "Header: value"  # Add custom headers
     45 -X METHOD           # HTTP method (GET, POST, PUT, DELETE, etc.)
     46 -d "data"           # POST data
     47 -t THREADS          # Number of concurrent threads (default: 40)
     48 -p DELAY            # Delay between requests (e.g., 0.1-2.0 seconds)
     49 -rate RATE          # Rate of requests per second
     50 -timeout SECONDS    # HTTP request timeout (default: 10)
     51 -v                  # Verbose output
     52 -s                  # Silent mode (no banner)
     53 -c                  # Colorize output
     54 -o FILE             # Output file
     55 -of FORMAT          # Output format (json, ejson, html, md, csv, ecsv)
     56 -recursion          # Enable recursive scanning
     57 -recursion-depth N  # Maximum recursion depth (default: 0)
     58 -e EXTENSIONS       # Comma-separated list of extensions to fuzz
     59 ```
     60 
     61 ## Fuzzing Keywords
     62 
     63 ffuf supports multiple fuzzing positions in the same request:
     64 
     65 ```bash
     66 FUZZ     # Primary fuzzing keyword
     67 FUZ2Z    # Secondary fuzzing keyword
     68 FUZ3Z    # Tertiary fuzzing keyword
     69 # ... up to FUZ99Z
     70 ```
     71 
     72 ### Examples
     73 
     74 ```bash
     75 # Single keyword
     76 ffuf -u https://example.com/FUZZ -w wordlist.txt
     77 
     78 # Multiple keywords
     79 ffuf -u https://example.com/FUZZ/FUZ2Z -w wordlist1.txt:FUZZ -w wordlist2.txt:FUZ2Z
     80 
     81 # Extension fuzzing
     82 ffuf -u https://example.com/file.FUZZ -w extensions.txt
     83 ```
     84 
     85 ## FUZZ Keyword Placement Guide
     86 
     87 This section shows **where** to place the FUZZ keyword to fuzz different parts of requests.
     88 
     89 ### 1. DNS/Subdomain Fuzzing
     90 
     91 ```bash
     92 # Subdomain enumeration (DNS FUZZ.website.com)
     93 ffuf -u https://FUZZ.example.com -w subdomains.txt
     94 
     95 # Multi-level subdomain fuzzing
     96 ffuf -u https://FUZZ.FUZ2Z.example.com \
     97      -w sub1.txt:FUZZ -w sub2.txt:FUZ2Z
     98 
     99 # Real example with common wordlist
    100 ffuf -u https://FUZZ.google.com \
    101      -w /opt/SecLists/Discovery/DNS/subdomains-top1million-5000.txt
    102 
    103 # With filtering to remove false positives
    104 ffuf -u https://FUZZ.example.com -w subdomains.txt -fs 1234
    105 
    106 # With custom DNS server
    107 ffuf -u https://FUZZ.example.com -w subdomains.txt -dns-server 8.8.8.8
    108 ```
    109 
    110 ### 2. URL Path/Directory Fuzzing
    111 
    112 ```bash
    113 # Single directory level
    114 ffuf -u https://example.com/FUZZ -w directories.txt
    115 
    116 # Nested directory paths
    117 ffuf -u https://example.com/api/FUZZ/users -w endpoints.txt
    118 
    119 # Two-level directory fuzzing
    120 ffuf -u https://example.com/FUZZ/FUZ2Z \
    121      -w dirs.txt:FUZZ -w subdirs.txt:FUZ2Z
    122 
    123 # Deep path fuzzing
    124 ffuf -u https://example.com/app/v1/FUZZ/config -w paths.txt
    125 
    126 # Fuzz entire path
    127 ffuf -u https://example.com/FUZZ -w full-paths.txt
    128 # Where full-paths.txt contains: admin/login, api/v1/users, etc.
    129 ```
    130 
    131 ### 3. Filename Fuzzing
    132 
    133 ```bash
    134 # Fuzz filename only
    135 ffuf -u https://example.com/admin/FUZZ.php -w filenames.txt
    136 
    137 # Fuzz filename and extension separately
    138 ffuf -u https://example.com/FUZZ.FUZ2Z \
    139      -w filenames.txt:FUZZ -w extensions.txt:FUZ2Z
    140 
    141 # Examples with filenames and extensions
    142 ffuf -u https://example.com/FUZZ.FUZ2Z \
    143      -w <(echo -e "index\nadmin\nconfig") \
    144      -w <(echo -e "php\nhtml\nbak\nold")
    145 ```
    146 
    147 ### 4. File Extension Fuzzing
    148 
    149 ```bash
    150 # Extension discovery
    151 ffuf -u https://example.com/config.FUZZ -w extensions.txt
    152 
    153 # With -e flag for automatic extension appending
    154 ffuf -u https://example.com/FUZZ -w files.txt -e .php,.html,.txt,.bak
    155 
    156 # Testing backup file extensions
    157 ffuf -u https://example.com/index.php.FUZZ \
    158      -w <(echo -e "bak\nold\n~\nswp\ntmp\nbackup")
    159 ```
    160 
    161 ### 5. GET Parameter Fuzzing
    162 
    163 ```bash
    164 # Fuzz parameter NAME
    165 ffuf -u "https://example.com/search?FUZZ=value" -w parameters.txt
    166 
    167 # Fuzz parameter VALUE
    168 ffuf -u "https://example.com/search?id=FUZZ" -w values.txt
    169 
    170 # Fuzz multiple parameters
    171 ffuf -u "https://example.com/api?FUZZ=1&FUZ2Z=2" \
    172      -w params1.txt:FUZZ -w params2.txt:FUZ2Z
    173 
    174 # Fuzz both parameter name AND value
    175 ffuf -u "https://example.com?FUZZ=FUZ2Z" \
    176      -w param-names.txt:FUZZ -w param-values.txt:FUZ2Z
    177 
    178 # Multiple existing parameters with one fuzzed
    179 ffuf -u "https://example.com/search?user=admin&id=FUZZ&page=1" \
    180      -w ids.txt
    181 
    182 # Testing for hidden parameters
    183 ffuf -u "https://example.com/profile?user=john&FUZZ=test" \
    184      -w param-names.txt -fw 100
    185 ```
    186 
    187 ### 6. Virtual Host (VHOST) Header Fuzzing
    188 
    189 ```bash
    190 # Basic VHOST fuzzing (subdomain in Host header)
    191 ffuf -u http://10.10.10.10 -H "Host: FUZZ.example.com" -w vhosts.txt
    192 
    193 # Fuzz entire hostname
    194 ffuf -u http://192.168.1.100 -H "Host: FUZZ" -w hostnames.txt
    195 
    196 # VHOST with port
    197 ffuf -u http://example.com -H "Host: FUZZ.example.com:8080" -w vhosts.txt
    198 
    199 # Filter false positives by response size
    200 ffuf -u http://10.10.10.10 -H "Host: FUZZ.local" -w vhosts.txt -fs 1234
    201 ```
    202 
    203 ### 7. HTTP Header Fuzzing
    204 
    205 ```bash
    206 # Fuzz header VALUE
    207 ffuf -u https://example.com -H "X-Custom-Header: FUZZ" -w values.txt
    208 
    209 # Fuzz header NAME
    210 ffuf -u https://example.com -H "FUZZ: testvalue" -w header-names.txt
    211 
    212 # Fuzz User-Agent
    213 ffuf -u https://example.com -H "User-Agent: FUZZ" -w user-agents.txt
    214 
    215 # Fuzz X-Forwarded-For (IP spoofing)
    216 ffuf -u https://example.com -H "X-Forwarded-For: FUZZ" -w ips.txt
    217 
    218 # Multiple header fuzzing
    219 ffuf -u https://example.com \
    220      -H "X-Forwarded-For: FUZZ" \
    221      -H "X-Real-IP: FUZ2Z" \
    222      -w ips.txt:FUZZ -w ips.txt:FUZ2Z
    223 
    224 # Authorization header fuzzing
    225 ffuf -u https://example.com/admin -H "Authorization: Bearer FUZZ" \
    226      -w tokens.txt
    227 
    228 # Custom API key header
    229 ffuf -u https://api.example.com -H "X-API-Key: FUZZ" -w api-keys.txt
    230 ```
    231 
    232 ### 8. POST Data Fuzzing
    233 
    234 ```bash
    235 # Fuzz POST parameter VALUE (form data)
    236 ffuf -u https://example.com/login -X POST \
    237      -d "username=admin&password=FUZZ" \
    238      -w passwords.txt \
    239      -H "Content-Type: application/x-www-form-urlencoded"
    240 
    241 # Fuzz POST parameter NAME
    242 ffuf -u https://example.com/api -X POST \
    243      -d "FUZZ=testvalue" \
    244      -w param-names.txt \
    245      -H "Content-Type: application/x-www-form-urlencoded"
    246 
    247 # Fuzz both username AND password
    248 ffuf -u https://example.com/login -X POST \
    249      -d "username=FUZZ&password=FUZ2Z" \
    250      -w usernames.txt:FUZZ -w passwords.txt:FUZ2Z
    251 
    252 # Fuzz multiple POST fields
    253 ffuf -u https://example.com/register -X POST \
    254      -d "email=FUZZ@example.com&username=FUZ2Z&role=FUZ3Z" \
    255      -w emails.txt:FUZZ -w users.txt:FUZ2Z -w roles.txt:FUZ3Z
    256 ```
    257 
    258 ### 9. JSON Data Fuzzing
    259 
    260 ```bash
    261 # Fuzz JSON field VALUE
    262 ffuf -u https://api.example.com/auth -X POST \
    263      -d '{"username":"admin","password":"FUZZ"}' \
    264      -w passwords.txt \
    265      -H "Content-Type: application/json"
    266 
    267 # Fuzz JSON field NAME
    268 ffuf -u https://api.example.com/data -X POST \
    269      -d '{"FUZZ":"value"}' \
    270      -w field-names.txt \
    271      -H "Content-Type: application/json"
    272 
    273 # Fuzz nested JSON values
    274 ffuf -u https://api.example.com/user -X POST \
    275      -d '{"user":{"name":"admin","role":"FUZZ"}}' \
    276      -w roles.txt \
    277      -H "Content-Type: application/json"
    278 
    279 # Fuzz array elements in JSON
    280 ffuf -u https://api.example.com/permissions -X POST \
    281      -d '{"permissions":["read","FUZZ"]}' \
    282      -w permissions.txt \
    283      -H "Content-Type: application/json"
    284 ```
    285 
    286 ### 10. Cookie Fuzzing
    287 
    288 ```bash
    289 # Fuzz cookie VALUE
    290 ffuf -u https://example.com -b "session=FUZZ" -w sessions.txt
    291 
    292 # Fuzz cookie NAME
    293 ffuf -u https://example.com -b "FUZZ=value123" -w cookie-names.txt
    294 
    295 # Multiple cookies with one fuzzed
    296 ffuf -u https://example.com -b "session=abc123; token=FUZZ; user=john" \
    297      -w tokens.txt
    298 
    299 # Fuzz multiple cookies simultaneously
    300 ffuf -u https://example.com -b "session=FUZZ; userid=FUZ2Z" \
    301      -w sessions.txt:FUZZ -w userids.txt:FUZ2Z
    302 
    303 # Using -H header instead of -b
    304 ffuf -u https://example.com \
    305      -H "Cookie: session=FUZZ; token=xyz" \
    306      -w sessions.txt
    307 ```
    308 
    309 ### 11. Protocol & Port Fuzzing
    310 
    311 ```bash
    312 # Fuzz protocol (http vs https)
    313 ffuf -u FUZZ://api.example.com -w <(echo -e "http\nhttps")
    314 
    315 # Fuzz port numbers
    316 ffuf -u https://example.com:FUZZ -w ports.txt
    317 # Where ports.txt: 80, 443, 8080, 8443, 3000, 8000, etc.
    318 
    319 # Fuzz subdomain and port together
    320 ffuf -u https://FUZZ.example.com:FUZ2Z \
    321      -w subdomains.txt:FUZZ -w ports.txt:FUZ2Z
    322 ```
    323 
    324 ### 12. Username in URL Path
    325 
    326 ```bash
    327 # Fuzz username/userid in path
    328 ffuf -u https://example.com/users/FUZZ -w usernames.txt
    329 
    330 # Fuzz numeric user IDs
    331 seq 1 1000 | ffuf -u https://example.com/profile/FUZZ -w -
    332 
    333 # Fuzz UUID format IDs
    334 ffuf -u https://api.example.com/document/FUZZ -w uuids.txt
    335 ```
    336 
    337 ### 13. Fragment/Anchor Fuzzing
    338 
    339 ```bash
    340 # Fuzz URL fragment (after #)
    341 ffuf -u https://example.com/page#FUZZ -w fragments.txt
    342 # Note: Fragments are typically client-side, but can reveal info
    343 ```
    344 
    345 ### 14. File Upload Parameter Fuzzing
    346 
    347 ```bash
    348 # Fuzz file upload field name
    349 ffuf -u https://example.com/upload -X POST \
    350      -F "FUZZ=@/path/to/file.txt" \
    351      -w field-names.txt
    352 
    353 # Fuzz file content type
    354 ffuf -u https://example.com/upload -X POST \
    355      -F "file=@test.txt;type=FUZZ" \
    356      -w content-types.txt
    357 ```
    358 
    359 ### 15. Authentication Fuzzing
    360 
    361 ```bash
    362 # Basic Auth username fuzzing
    363 echo -n "FUZZ:password" | base64 | \
    364     ffuf -u https://example.com -H "Authorization: Basic $(cat -)" -w usernames.txt
    365 
    366 # Bearer token fuzzing
    367 ffuf -u https://api.example.com/admin \
    368      -H "Authorization: Bearer FUZZ" \
    369      -w tokens.txt
    370 
    371 # API key in URL parameter
    372 ffuf -u "https://api.example.com/data?apikey=FUZZ" -w keys.txt
    373 ```
    374 
    375 ### 16. Query String Injection Points
    376 
    377 ```bash
    378 # Fuzz inside existing query value (SQL injection testing)
    379 ffuf -u "https://example.com/search?id=1FUZZ" -w sqli-payloads.txt
    380 
    381 # Fuzz before parameter (path confusion)
    382 ffuf -u "https://example.com/FUZZ?id=123" -w paths.txt
    383 
    384 # Multiple injection points in same URL
    385 ffuf -u "https://example.com/FUZZ?param=FUZ2Z&data=FUZ3Z" \
    386      -w paths.txt:FUZZ -w values.txt:FUZ2Z -w data.txt:FUZ3Z
    387 ```
    388 
    389 ### 17. GraphQL Fuzzing
    390 
    391 ```bash
    392 # Fuzz GraphQL query
    393 ffuf -u https://api.example.com/graphql -X POST \
    394      -d '{"query":"{ FUZZ { id name } }"}' \
    395      -w graphql-types.txt \
    396      -H "Content-Type: application/json"
    397 
    398 # Fuzz GraphQL field
    399 ffuf -u https://api.example.com/graphql -X POST \
    400      -d '{"query":"{ users { FUZZ } }"}' \
    401      -w field-names.txt \
    402      -H "Content-Type: application/json"
    403 ```
    404 
    405 ### 18. REST API Resource Fuzzing
    406 
    407 ```bash
    408 # Fuzz API version
    409 ffuf -u https://api.example.com/FUZZ/users -w api-versions.txt
    410 # Where api-versions.txt: v1, v2, v3, api/v1, etc.
    411 
    412 # Fuzz API resource type
    413 ffuf -u https://api.example.com/api/v1/FUZZ -w resources.txt
    414 # Where resources.txt: users, posts, comments, products, etc.
    415 
    416 # Fuzz resource ID
    417 ffuf -u https://api.example.com/api/v1/users/FUZZ -w ids.txt
    418 ```
    419 
    420 ### 19. Advanced Multi-Position Fuzzing
    421 
    422 ```bash
    423 # Clusterbomb mode - ALL combinations (file.ext)
    424 ffuf -mode clusterbomb \
    425      -u https://example.com/FUZZ.FUZ2Z \
    426      -w filenames.txt:FUZZ \
    427      -w extensions.txt:FUZ2Z
    428 
    429 # Pitchfork mode - Parallel iteration (line by line)
    430 ffuf -mode pitchfork \
    431      -u https://example.com/FUZZ \
    432      -w urls.txt:FUZZ \
    433      -w specific-values.txt:FUZ2Z
    434 
    435 # Three fuzzing positions
    436 ffuf -u https://FUZZ.example.com/FUZ2Z/FUZ3Z \
    437      -w subdomains.txt:FUZZ \
    438      -w dirs.txt:FUZ2Z \
    439      -w files.txt:FUZ3Z
    440 ```
    441 
    442 ### 20. Special Characters & Encoding
    443 
    444 ```bash
    445 # URL-encoded fuzzing
    446 ffuf -u "https://example.com/search?q=FUZZ" -w encoded-payloads.txt
    447 
    448 # Double URL encoding
    449 ffuf -u "https://example.com/path/FUZZ" -w double-encoded.txt
    450 
    451 # Base64 encoded values
    452 ffuf -u https://example.com/data/FUZZ -w base64-values.txt
    453 
    454 # Fuzz with special characters (testing WAF bypass)
    455 ffuf -u "https://example.com/FUZZ" -w special-chars.txt
    456 ```
    457 
    458 ### FUZZ Placement Quick Reference Table
    459 
    460 | Target | Example | Wordlist Type |
    461 |--------|---------|---------------|
    462 | **Subdomain** | `https://FUZZ.example.com` | subdomains.txt |
    463 | **Directory** | `https://example.com/FUZZ` | directories.txt |
    464 | **File** | `https://example.com/admin/FUZZ.php` | filenames.txt |
    465 | **Extension** | `https://example.com/config.FUZZ` | extensions.txt |
    466 | **GET Param Name** | `https://example.com?FUZZ=value` | parameters.txt |
    467 | **GET Param Value** | `https://example.com?id=FUZZ` | values.txt |
    468 | **POST Data** | `-d "user=admin&pass=FUZZ"` | passwords.txt |
    469 | **JSON Value** | `-d '{"user":"FUZZ"}'` | usernames.txt |
    470 | **Header Value** | `-H "X-Auth: FUZZ"` | tokens.txt |
    471 | **Cookie Value** | `-b "session=FUZZ"` | sessions.txt |
    472 | **VHOST** | `-H "Host: FUZZ.local"` | vhosts.txt |
    473 | **Port** | `https://example.com:FUZZ` | ports.txt |
    474 | **User ID** | `https://site.com/user/FUZZ` | userids.txt |
    475 
    476 ## Common Use Cases
    477 
    478 ### 1. Directory & File Fuzzing
    479 
    480 ```bash
    481 # Basic directory enumeration
    482 ffuf -u https://example.com/FUZZ -w /usr/share/wordlists/dirb/common.txt
    483 
    484 # Directory fuzzing with extensions
    485 ffuf -u https://example.com/FUZZ -w wordlist.txt -e .php,.html,.txt,.bak
    486 
    487 # File extension enumeration
    488 ffuf -u https://example.com/admin.FUZZ -w extensions.txt
    489 
    490 # Recursive directory scanning
    491 ffuf -u https://example.com/FUZZ -w wordlist.txt -recursion -recursion-depth 2
    492 
    493 # Only show 200 responses
    494 ffuf -u https://example.com/FUZZ -w wordlist.txt -mc 200
    495 ```
    496 
    497 ### 2. Subdomain Enumeration
    498 
    499 ```bash
    500 # Basic subdomain fuzzing
    501 ffuf -u https://FUZZ.example.com -w subdomains.txt
    502 
    503 # With custom DNS server
    504 ffuf -u https://FUZZ.example.com -w subdomains.txt -dns-server 8.8.8.8
    505 
    506 # Filtering by response size
    507 ffuf -u https://FUZZ.example.com -w subdomains.txt -fs 4242
    508 ```
    509 
    510 ### 3. Virtual Host Discovery
    511 
    512 ```bash
    513 # VHOST enumeration
    514 ffuf -u https://example.com -H "Host: FUZZ.example.com" -w wordlist.txt
    515 
    516 # Filter false positives by size
    517 ffuf -u https://10.10.10.10 -H "Host: FUZZ.example.local" -w wordlist.txt -fs 1234
    518 
    519 # Multiple header fuzzing
    520 ffuf -u https://example.com -H "Host: FUZZ" -H "X-Forwarded-For: FUZ2Z" \
    521      -w vhosts.txt:FUZZ -w ips.txt:FUZ2Z
    522 ```
    523 
    524 ### 4. Parameter Fuzzing (GET)
    525 
    526 ```bash
    527 # GET parameter discovery
    528 ffuf -u https://example.com?FUZZ=test -w params.txt
    529 
    530 # Multiple parameters
    531 ffuf -u https://example.com?FUZZ=FUZ2Z -w params.txt:FUZZ -w values.txt:FUZ2Z
    532 
    533 # Parameter value fuzzing
    534 ffuf -u https://example.com?id=FUZZ -w numbers.txt
    535 
    536 # Filter by response size
    537 ffuf -u https://example.com?page=FUZZ -w wordlist.txt -fs 0
    538 ```
    539 
    540 ### 5. POST Data Fuzzing
    541 
    542 ```bash
    543 # POST parameter fuzzing
    544 ffuf -u https://example.com/login -X POST -d "username=admin&password=FUZZ" \
    545      -w passwords.txt -H "Content-Type: application/x-www-form-urlencoded"
    546 
    547 # JSON POST fuzzing
    548 ffuf -u https://example.com/api -X POST \
    549      -d '{"username":"admin","password":"FUZZ"}' \
    550      -w passwords.txt -H "Content-Type: application/json"
    551 
    552 # Username and password fuzzing
    553 ffuf -u https://example.com/login -X POST \
    554      -d "username=FUZZ&password=FUZ2Z" \
    555      -w usernames.txt:FUZZ -w passwords.txt:FUZ2Z
    556 ```
    557 
    558 ### 6. API Endpoint Fuzzing
    559 
    560 ```bash
    561 # API endpoint discovery
    562 ffuf -u https://api.example.com/v1/FUZZ -w api-endpoints.txt
    563 
    564 # API version fuzzing
    565 ffuf -u https://api.example.com/FUZZ/users -w versions.txt
    566 
    567 # RESTful API fuzzing
    568 ffuf -u https://api.example.com/api/FUZZ -w wordlist.txt \
    569      -H "Authorization: Bearer TOKEN"
    570 ```
    571 
    572 ### 7. Username Enumeration
    573 
    574 ```bash
    575 # Login form username enumeration
    576 ffuf -u https://example.com/login -X POST \
    577      -d "username=FUZZ&password=invalid" \
    578      -w usernames.txt -mr "Invalid password"
    579 
    580 # User profile enumeration
    581 ffuf -u https://example.com/users/FUZZ -w usernames.txt -mc 200
    582 
    583 # Email enumeration
    584 ffuf -u https://example.com/forgot-password -X POST \
    585      -d "email=FUZZ@example.com" -w wordlist.txt -mr "sent"
    586 ```
    587 
    588 ### 8. File Backup Enumeration
    589 
    590 ```bash
    591 # Common backup extensions
    592 ffuf -u https://example.com/admin.FUZZ -w backup-extensions.txt
    593 
    594 # Backup file patterns
    595 ffuf -u https://example.com/FUZZ -w backup-patterns.txt
    596 # Where backup-patterns.txt contains: index.php.bak, index.php~, index.php.old, etc.
    597 
    598 # Combined filename and extension fuzzing
    599 ffuf -u https://example.com/FUZZ.FUZ2Z \
    600      -w filenames.txt:FUZZ -w extensions.txt:FUZ2Z
    601 ```
    602 
    603 ## Filter Options
    604 
    605 Filters HIDE matching responses (exclude from results):
    606 
    607 ```bash
    608 -fc CODE1,CODE2     # Filter HTTP status codes
    609 -fs SIZE1,SIZE2     # Filter response size (bytes)
    610 -fw WORDS1,WORDS2   # Filter word count
    611 -fl LINES1,LINES2   # Filter line count
    612 -fr REGEX           # Filter responses matching regex
    613 -ft TIME            # Filter response time (milliseconds)
    614 ```
    615 
    616 ### Filter Examples
    617 
    618 ```bash
    619 # Hide 404 and 403 responses
    620 ffuf -u https://example.com/FUZZ -w wordlist.txt -fc 404,403
    621 
    622 # Hide responses of specific size
    623 ffuf -u https://example.com/FUZZ -w wordlist.txt -fs 4242
    624 
    625 # Hide responses with specific word count
    626 ffuf -u https://FUZZ.example.com -w subdomains.txt -fw 1337
    627 
    628 # Hide responses matching "Not Found"
    629 ffuf -u https://example.com/FUZZ -w wordlist.txt -fr "Not Found"
    630 
    631 # Combine multiple filters
    632 ffuf -u https://example.com/FUZZ -w wordlist.txt -fc 404,403 -fs 0 -fw 1
    633 ```
    634 
    635 ## Matcher Options
    636 
    637 Matchers SHOW matching responses (include in results):
    638 
    639 ```bash
    640 -mc CODE1,CODE2     # Match HTTP status codes
    641 -ms SIZE1,SIZE2     # Match response size (bytes)
    642 -mw WORDS1,WORDS2   # Match word count
    643 -ml LINES1,LINES2   # Match line count
    644 -mr REGEX           # Match responses containing regex
    645 -mt TIME            # Match response time (milliseconds)
    646 ```
    647 
    648 ### Matcher Examples
    649 
    650 ```bash
    651 # Only show 200 and 301 responses
    652 ffuf -u https://example.com/FUZZ -w wordlist.txt -mc 200,301
    653 
    654 # Match specific response size
    655 ffuf -u https://example.com/FUZZ -w wordlist.txt -ms 1337
    656 
    657 # Match responses containing "success"
    658 ffuf -u https://example.com/login -X POST -d "user=admin&pass=FUZZ" \
    659      -w passwords.txt -mr "success"
    660 
    661 # Match slow responses (potential SQL injection)
    662 ffuf -u https://example.com/search?q=FUZZ -w sqli-payloads.txt -mt ">3000"
    663 
    664 # Combine matchers
    665 ffuf -u https://example.com/FUZZ -w wordlist.txt -mc 200 -ms 1000-5000
    666 ```
    667 
    668 ## Rate Limiting & Performance
    669 
    670 ```bash
    671 # Set number of threads (default: 40)
    672 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 100
    673 
    674 # Rate limiting (requests per second)
    675 ffuf -u https://example.com/FUZZ -w wordlist.txt -rate 10
    676 
    677 # Add delay between requests (seconds)
    678 ffuf -u https://example.com/FUZZ -w wordlist.txt -p 0.5
    679 
    680 # Set timeout (default: 10s)
    681 ffuf -u https://example.com/FUZZ -w wordlist.txt -timeout 30
    682 
    683 # Max execution time (seconds)
    684 ffuf -u https://example.com/FUZZ -w wordlist.txt -maxtime 600
    685 
    686 # Stop after errors
    687 ffuf -u https://example.com/FUZZ -w wordlist.txt -se
    688 ```
    689 
    690 ### Performance Tips
    691 
    692 ```bash
    693 # Fast scan (more threads, higher rate)
    694 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 200 -rate 100
    695 
    696 # Stealth scan (slower, less noise)
    697 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 5 -rate 2 -p 1
    698 
    699 # Balanced scan
    700 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 40 -rate 50
    701 ```
    702 
    703 ## Output Formats
    704 
    705 ```bash
    706 # Save output to file
    707 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.txt
    708 
    709 # JSON output
    710 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.json -of json
    711 
    712 # HTML report
    713 ffuf -u https://example.com/FUZZ -w wordlist.txt -o report.html -of html
    714 
    715 # Markdown output
    716 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.md -of md
    717 
    718 # CSV output
    719 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.csv -of csv
    720 
    721 # eJSON (one JSON per line - easy to parse)
    722 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.ejson -of ejson
    723 
    724 # CSV with base64 (includes response body)
    725 ffuf -u https://example.com/FUZZ -w wordlist.txt -o results.csv -of ecsv
    726 ```
    727 
    728 ### Output Parsing Examples
    729 
    730 ```bash
    731 # Parse JSON output with jq
    732 cat results.json | jq '.results[] | select(.status == 200) | .url'
    733 
    734 # Extract URLs from eJSON
    735 cat results.ejson | jq -r '.url'
    736 
    737 # Filter by status code
    738 cat results.ejson | jq -r 'select(.status == 200) | .url'
    739 ```
    740 
    741 ## Authentication
    742 
    743 ### Basic Authentication
    744 
    745 ```bash
    746 # Basic auth
    747 ffuf -u https://example.com/FUZZ -w wordlist.txt -H "Authorization: Basic dXNlcjpwYXNz"
    748 
    749 # Or use base64 directly
    750 echo -n "username:password" | base64
    751 ffuf -u https://example.com/FUZZ -w wordlist.txt -H "Authorization: Basic BASE64_HERE"
    752 ```
    753 
    754 ### Bearer Token
    755 
    756 ```bash
    757 # JWT/Bearer token
    758 ffuf -u https://api.example.com/FUZZ -w wordlist.txt \
    759      -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
    760 ```
    761 
    762 ### Cookie-Based Authentication
    763 
    764 ```bash
    765 # Using cookies
    766 ffuf -u https://example.com/FUZZ -w wordlist.txt \
    767      -b "session=abc123; token=xyz789"
    768 
    769 # Or with header
    770 ffuf -u https://example.com/FUZZ -w wordlist.txt \
    771      -H "Cookie: session=abc123; token=xyz789"
    772 ```
    773 
    774 ### Custom Authentication Header
    775 
    776 ```bash
    777 # API key
    778 ffuf -u https://api.example.com/FUZZ -w wordlist.txt \
    779      -H "X-API-Key: your-api-key-here"
    780 
    781 # Multiple auth headers
    782 ffuf -u https://example.com/FUZZ -w wordlist.txt \
    783      -H "X-API-Key: key123" \
    784      -H "X-Auth-Token: token456"
    785 ```
    786 
    787 ## HTTP Methods
    788 
    789 ```bash
    790 # GET (default)
    791 ffuf -u https://example.com/FUZZ -w wordlist.txt
    792 
    793 # POST
    794 ffuf -u https://example.com/api/FUZZ -X POST -w wordlist.txt
    795 
    796 # PUT
    797 ffuf -u https://example.com/api/users/FUZZ -X PUT \
    798      -d '{"data":"value"}' -w wordlist.txt
    799 
    800 # DELETE
    801 ffuf -u https://example.com/api/users/FUZZ -X DELETE -w wordlist.txt
    802 
    803 # HEAD (faster for discovery)
    804 ffuf -u https://example.com/FUZZ -X HEAD -w wordlist.txt
    805 
    806 # OPTIONS (enumerate HTTP methods)
    807 ffuf -u https://example.com/FUZZ -X OPTIONS -w wordlist.txt
    808 
    809 # PATCH
    810 ffuf -u https://example.com/api/users/FUZZ -X PATCH \
    811      -d '{"field":"value"}' -w wordlist.txt
    812 ```
    813 
    814 ## Advanced Techniques
    815 
    816 ### 1. Recursive Scanning
    817 
    818 ```bash
    819 # Enable recursion
    820 ffuf -u https://example.com/FUZZ -w wordlist.txt -recursion
    821 
    822 # Set recursion depth
    823 ffuf -u https://example.com/FUZZ -w wordlist.txt -recursion -recursion-depth 3
    824 
    825 # Recursion with custom strategy
    826 ffuf -u https://example.com/FUZZ -w wordlist.txt \
    827      -recursion -recursion-depth 2 -recursion-strategy greedy
    828 ```
    829 
    830 ### 2. Replay Proxy (for Burp Suite/OWASP ZAP)
    831 
    832 ```bash
    833 # Send requests through proxy
    834 ffuf -u https://example.com/FUZZ -w wordlist.txt \
    835      -replay-proxy http://127.0.0.1:8080
    836 
    837 # With proxy authentication
    838 ffuf -u https://example.com/FUZZ -w wordlist.txt \
    839      -replay-proxy http://user:pass@127.0.0.1:8080
    840 ```
    841 
    842 ### 3. Client Certificates
    843 
    844 ```bash
    845 # Using client certificate
    846 ffuf -u https://example.com/FUZZ -w wordlist.txt \
    847      -cert /path/to/cert.pem -key /path/to/key.pem
    848 ```
    849 
    850 ### 4. Custom SNI
    851 
    852 ```bash
    853 # Server Name Indication
    854 ffuf -u https://10.10.10.10/FUZZ -w wordlist.txt -sni example.com
    855 ```
    856 
    857 ### 5. Follow Redirects
    858 
    859 ```bash
    860 # Follow redirects
    861 ffuf -u https://example.com/FUZZ -w wordlist.txt -r
    862 
    863 # Max redirect depth
    864 ffuf -u https://example.com/FUZZ -w wordlist.txt -r -maxredirs 5
    865 ```
    866 
    867 ### 6. Auto-Calibration
    868 
    869 ```bash
    870 # Auto-calibrate filters (removes false positives)
    871 ffuf -u https://example.com/FUZZ -w wordlist.txt -ac
    872 
    873 # Auto-calibration with custom strategy
    874 ffuf -u https://example.com/FUZZ -w wordlist.txt -ac -acc 95
    875 ```
    876 
    877 ### 7. Request/Response Inspection
    878 
    879 ```bash
    880 # Show request/response for debugging
    881 ffuf -u https://example.com/FUZZ -w wordlist.txt -v
    882 
    883 # Show only specific status codes in verbose
    884 ffuf -u https://example.com/FUZZ -w wordlist.txt -mc 200 -v
    885 ```
    886 
    887 ### 8. Custom User-Agent
    888 
    889 ```bash
    890 # Custom User-Agent
    891 ffuf -u https://example.com/FUZZ -w wordlist.txt \
    892      -H "User-Agent: Mozilla/5.0 (custom)"
    893 
    894 # Random User-Agent per request (requires UA wordlist)
    895 ffuf -u https://example.com/FUZZ -w dirs.txt:FUZZ -w user-agents.txt:USERAGENT \
    896      -H "User-Agent: USERAGENT"
    897 ```
    898 
    899 ### 9. Input Modes
    900 
    901 ```bash
    902 # Clusterbomb mode (cartesian product)
    903 ffuf -mode clusterbomb -u https://example.com/FUZZ/FUZ2Z \
    904      -w wordlist1.txt:FUZZ -w wordlist2.txt:FUZ2Z
    905 
    906 # Pitchfork mode (parallel iteration)
    907 ffuf -mode pitchfork -u https://example.com/FUZZ \
    908      -w wordlist1.txt:FUZZ -w wordlist2.txt:FUZ2Z
    909 ```
    910 
    911 ### 10. Input from stdin
    912 
    913 ```bash
    914 # Use stdin as wordlist
    915 cat wordlist.txt | ffuf -u https://example.com/FUZZ -w -
    916 
    917 # Combine with other tools
    918 cat targets.txt | httpx -silent | ffuf -u FUZZ/admin -w -
    919 ```
    920 
    921 ## Common Wordlists
    922 
    923 ### SecLists (Recommended)
    924 
    925 ```bash
    926 # Install SecLists
    927 git clone https://github.com/danielmiessler/SecLists.git /opt/SecLists
    928 ```
    929 
    930 ### Directory & File Discovery
    931 
    932 ```text
    933 /usr/share/wordlists/dirb/common.txt
    934 /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
    935 /opt/SecLists/Discovery/Web-Content/directory-list-2.3-medium.txt
    936 /opt/SecLists/Discovery/Web-Content/raft-large-directories.txt
    937 /opt/SecLists/Discovery/Web-Content/big.txt
    938 /opt/SecLists/Discovery/Web-Content/common.txt
    939 ```
    940 
    941 ### Subdomains
    942 
    943 ```text
    944 /opt/SecLists/Discovery/DNS/subdomains-top1million-5000.txt
    945 /opt/SecLists/Discovery/DNS/subdomains-top1million-20000.txt
    946 /opt/SecLists/Discovery/DNS/subdomains-top1million-110000.txt
    947 /opt/SecLists/Discovery/DNS/bitquark-subdomains-top100000.txt
    948 ```
    949 
    950 ### Parameters
    951 
    952 ```text
    953 /opt/SecLists/Discovery/Web-Content/burp-parameter-names.txt
    954 /opt/SecLists/Discovery/Web-Content/api/api-endpoints.txt
    955 /opt/SecLists/Discovery/Web-Content/common-api-endpoints-mazen160.txt
    956 ```
    957 
    958 ### Usernames
    959 
    960 ```text
    961 /opt/SecLists/Usernames/Names/names.txt
    962 /opt/SecLists/Usernames/top-usernames-shortlist.txt
    963 /opt/SecLists/Usernames/xato-net-10-million-usernames.txt
    964 ```
    965 
    966 ### Passwords
    967 
    968 ```text
    969 /usr/share/wordlists/rockyou.txt
    970 /opt/SecLists/Passwords/Common-Credentials/10-million-password-list-top-1000000.txt
    971 /opt/SecLists/Passwords/darkweb2017-top10000.txt
    972 ```
    973 
    974 ### Extensions
    975 
    976 ```bash
    977 # Create custom extension list
    978 echo -e ".php\n.html\n.js\n.json\n.xml\n.bak\n.old\n.txt\n.asp\n.aspx\n.jsp" > extensions.txt
    979 ```
    980 
    981 ## Tips & Tricks
    982 
    983 ### 1. Finding the Right Filters
    984 
    985 ```bash
    986 # First run without filters to see baseline
    987 ffuf -u https://example.com/FUZZ -w wordlist.txt
    988 
    989 # Then add filters based on false positive patterns
    990 ffuf -u https://example.com/FUZZ -w wordlist.txt -fs 4242 -fw 337
    991 
    992 # Use auto-calibration
    993 ffuf -u https://example.com/FUZZ -w wordlist.txt -ac
    994 ```
    995 
    996 ### 2. Speed Optimization
    997 
    998 ```bash
    999 # Use HEAD method for faster discovery
   1000 ffuf -u https://example.com/FUZZ -w wordlist.txt -X HEAD
   1001 
   1002 # Increase threads for faster scanning
   1003 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 100
   1004 
   1005 # Use smaller wordlists first
   1006 ffuf -u https://example.com/FUZZ -w common.txt -t 50
   1007 ```
   1008 
   1009 ### 3. Stealth & Evasion
   1010 
   1011 ```bash
   1012 # Slow and steady
   1013 ffuf -u https://example.com/FUZZ -w wordlist.txt -t 5 -p 2 -rate 1
   1014 
   1015 # Randomize User-Agent
   1016 ffuf -u https://example.com/FUZZ -w dirs.txt:FUZZ -w ua.txt:UA \
   1017      -H "User-Agent: UA" -mode pitchfork
   1018 
   1019 # Add random delay
   1020 ffuf -u https://example.com/FUZZ -w wordlist.txt -p 0.5-2.0
   1021 ```
   1022 
   1023 ### 4. Finding Hidden Parameters
   1024 
   1025 ```bash
   1026 # GET parameter discovery with value testing
   1027 ffuf -u "https://example.com?FUZZ=test" -w params.txt -fw 100
   1028 
   1029 # POST parameter discovery
   1030 ffuf -u https://example.com/search -X POST \
   1031      -d "FUZZ=test" -w params.txt -H "Content-Type: application/x-www-form-urlencoded"
   1032 
   1033 # JSON parameter discovery
   1034 ffuf -u https://api.example.com/endpoint -X POST \
   1035      -d '{"FUZZ":"test"}' -w params.txt -H "Content-Type: application/json"
   1036 ```
   1037 
   1038 ### 5. Combining with Other Tools
   1039 
   1040 ```bash
   1041 # Chain with subfinder
   1042 subfinder -d example.com -silent | ffuf -u https://FUZZ/admin -w -
   1043 
   1044 # Chain with waybackurls
   1045 waybackurls example.com | grep -E "\.(js|php|asp)" | ffuf -u FUZZ -w -
   1046 
   1047 # Pipe to httpx for validation
   1048 ffuf -u https://example.com/FUZZ -w wordlist.txt -mc 200 -o urls.txt -of csv | \
   1049      awk -F, '{print $1}' | httpx -silent
   1050 ```
   1051 
   1052 ### 6. Pattern-Based Fuzzing
   1053 
   1054 ```bash
   1055 # Numeric ID fuzzing
   1056 seq 1 1000 | ffuf -u https://example.com/user/FUZZ -w -
   1057 
   1058 # Date-based fuzzing
   1059 for year in {2020..2024}; do
   1060     for month in {01..12}; do
   1061         echo "$year-$month"
   1062     done
   1063 done | ffuf -u https://example.com/archive/FUZZ -w -
   1064 
   1065 # Hex ID fuzzing
   1066 for i in {0..255}; do printf "%02x\n" $i; done | ffuf -u https://example.com/id/FUZZ -w -
   1067 ```
   1068 
   1069 ### 7. Response Size Ranges
   1070 
   1071 ```bash
   1072 # Match response size ranges
   1073 ffuf -u https://example.com/FUZZ -w wordlist.txt -ms 1000-5000
   1074 
   1075 # Filter size ranges
   1076 ffuf -u https://example.com/FUZZ -w wordlist.txt -fs 0-100
   1077 ```
   1078 
   1079 ### 8. Content-Type Fuzzing
   1080 
   1081 ```bash
   1082 # Fuzz Content-Type header
   1083 ffuf -u https://example.com/upload -X POST \
   1084      -d "data" -H "Content-Type: FUZZ" -w content-types.txt
   1085 # content-types.txt: application/json, application/xml, text/plain, multipart/form-data
   1086 ```
   1087 
   1088 ### 9. Debugging Failed Scans
   1089 
   1090 ```bash
   1091 # Verbose output with request/response
   1092 ffuf -u https://example.com/FUZZ -w wordlist.txt -v
   1093 
   1094 # Test with single word first
   1095 echo "test" | ffuf -u https://example.com/FUZZ -w - -v
   1096 
   1097 # Check DNS resolution
   1098 ffuf -u https://FUZZ.example.com -w subdomain.txt -debug-log debug.log
   1099 ```
   1100 
   1101 ### 10. Multiple Wordlist Strategies
   1102 
   1103 ```bash
   1104 # Clusterbomb (all combinations)
   1105 ffuf -mode clusterbomb -u https://example.com/FUZZ.FUZ2Z \
   1106      -w files.txt:FUZZ -w extensions.txt:FUZ2Z
   1107 
   1108 # Pitchfork (parallel - line by line)
   1109 ffuf -mode pitchfork -u https://example.com/FUZZ \
   1110      -w wordlist1.txt:FUZZ -w wordlist2.txt:FUZ2Z
   1111 ```
   1112 
   1113 ## Real-World Examples
   1114 
   1115 ### Example 1: Complete Web App Enumeration
   1116 
   1117 ```bash
   1118 # Step 1: Find directories
   1119 ffuf -u https://target.com/FUZZ -w common.txt -mc 200,301,302,401,403 -o dirs.json -of json
   1120 
   1121 # Step 2: Find files in discovered directories
   1122 ffuf -u https://target.com/admin/FUZZ -w files.txt -e .php,.html,.txt,.bak -mc 200
   1123 
   1124 # Step 3: Parameter discovery
   1125 ffuf -u "https://target.com/search?FUZZ=test" -w params.txt -fw 100
   1126 
   1127 # Step 4: Virtual host discovery
   1128 ffuf -u https://target.com -H "Host: FUZZ.target.com" -w vhosts.txt -fs 4242
   1129 ```
   1130 
   1131 ### Example 2: API Endpoint Discovery
   1132 
   1133 ```bash
   1134 # Find API endpoints
   1135 ffuf -u https://api.target.com/v1/FUZZ -w api-endpoints.txt -mc 200,401,403
   1136 
   1137 # Test different API versions
   1138 ffuf -u https://api.target.com/FUZZ/users -w api-versions.txt
   1139 
   1140 # Find API objects
   1141 ffuf -u https://api.target.com/api/v1/FUZZ -w api-objects.txt -H "Authorization: Bearer TOKEN"
   1142 
   1143 # Numeric ID enumeration
   1144 seq 1 10000 | ffuf -u https://api.target.com/api/v1/users/FUZZ -w - -mc 200
   1145 ```
   1146 
   1147 ### Example 3: Subdomain Takeover Check
   1148 
   1149 ```bash
   1150 # Find subdomains
   1151 ffuf -u https://FUZZ.target.com -w subdomains.txt -mc 200,301,302 -o subdomains.txt -of csv
   1152 
   1153 # Check for CNAME records
   1154 cat subdomains.txt | awk -F, '{print $1}' | while read sub; do
   1155     dig +short $sub CNAME
   1156 done
   1157 
   1158 # Check for common takeover patterns
   1159 ffuf -u https://FUZZ.target.com -w discovered-subs.txt -mr "NoSuchBucket|Repository not found|404"
   1160 ```
   1161 
   1162 ### Example 4: IDOR Testing
   1163 
   1164 ```bash
   1165 # Enumerate user IDs
   1166 seq 1 1000 | ffuf -u https://target.com/api/user/FUZZ -w - \
   1167      -H "Authorization: Bearer YOUR_TOKEN" -mc 200
   1168 
   1169 # Test UUID format
   1170 cat uuids.txt | ffuf -u https://target.com/api/document/FUZZ -w - \
   1171      -H "Cookie: session=xyz" -mc 200 -v
   1172 ```
   1173 
   1174 ### Example 5: SQLi & XSS Parameter Fuzzing
   1175 
   1176 ```bash
   1177 # Find injectable parameters (SQL injection)
   1178 ffuf -u "https://target.com/search?id=FUZZ" -w sqli-payloads.txt \
   1179      -mr "SQL syntax|mysql_fetch|error in your SQL" -v
   1180 
   1181 # XSS parameter fuzzing
   1182 ffuf -u "https://target.com/search?q=FUZZ" -w xss-payloads.txt \
   1183      -mr "<script>|alert\(1\)" -v
   1184 
   1185 # Slow response detection (time-based SQLi)
   1186 ffuf -u "https://target.com/search?id=FUZZ" -w time-sqli.txt -mt ">3000"
   1187 ```
   1188 
   1189 ### Example 6: WordPress Scanning
   1190 
   1191 ```bash
   1192 # Find WordPress plugins
   1193 ffuf -u https://target.com/wp-content/plugins/FUZZ/readme.txt -w wp-plugins.txt -mc 200
   1194 
   1195 # Find WordPress themes
   1196 ffuf -u https://target.com/wp-content/themes/FUZZ/style.css -w wp-themes.txt -mc 200
   1197 
   1198 # Find WordPress users
   1199 seq 1 100 | ffuf -u https://target.com/?author=FUZZ -w - -fc 404
   1200 
   1201 # WordPress xmlrpc brute force
   1202 ffuf -u https://target.com/xmlrpc.php -X POST \
   1203      -d '<methodCall><methodName>wp.getUsersBlogs</methodName><params><param><value>admin</value></param><param><value>FUZZ</value></param></params></methodCall>' \
   1204      -w passwords.txt -mr "isAdmin"
   1205 ```
   1206 
   1207 ### Example 7: Multi-Stage Fuzzing
   1208 
   1209 ```bash
   1210 # Stage 1: Find subdomains
   1211 ffuf -u https://FUZZ.target.com -w subdomains.txt -mc 200 -o stage1.json -of json
   1212 
   1213 # Stage 2: Extract live hosts and fuzz paths
   1214 cat stage1.json | jq -r '.results[].url' | while read url; do
   1215     ffuf -u $url/FUZZ -w paths.txt -mc 200,301,302
   1216 done
   1217 
   1218 # Stage 3: Fuzz parameters on discovered endpoints (manual, based on Stage 2)
   1219 ```
   1220 
   1221 ### Example 8: GraphQL Endpoint Enumeration
   1222 
   1223 ```bash
   1224 # Find GraphQL endpoint
   1225 ffuf -u https://target.com/FUZZ -w graphql-paths.txt -mc 200,400 -mr "graphql|query"
   1226 
   1227 # GraphQL introspection query fuzzing
   1228 ffuf -u https://target.com/graphql -X POST \
   1229      -d '{"query":"FUZZ"}' -w graphql-queries.txt \
   1230      -H "Content-Type: application/json" -mc 200
   1231 ```
   1232 
   1233 ### Example 9: Cloud Bucket Discovery
   1234 
   1235 ```bash
   1236 # S3 bucket enumeration
   1237 ffuf -u https://FUZZ.s3.amazonaws.com -w bucket-names.txt -mc 200,403
   1238 
   1239 # Azure blob storage
   1240 ffuf -u https://FUZZ.blob.core.windows.net -w storage-names.txt -mc 200,403
   1241 
   1242 # Google Cloud Storage
   1243 ffuf -u https://storage.googleapis.com/FUZZ -w bucket-names.txt -mc 200,403
   1244 ```
   1245 
   1246 ### Example 10: JWT Secret Fuzzing
   1247 
   1248 ```bash
   1249 # Fuzz JWT secrets (generate JWTs with FUZZ as secret using a script)
   1250 ffuf -u https://target.com/api/admin -X GET \
   1251      -H "Authorization: Bearer JWT_WITH_FUZZ_SECRET" \
   1252      -w jwt-secrets.txt -mc 200
   1253 ```
   1254 
   1255 ## Quick Reference Card
   1256 
   1257 ```bash
   1258 # Basic directory fuzzing
   1259 ffuf -u https://target.com/FUZZ -w wordlist.txt
   1260 
   1261 # With extensions
   1262 ffuf -u https://target.com/FUZZ -w wordlist.txt -e .php,.html,.txt
   1263 
   1264 # Subdomain enumeration
   1265 ffuf -u https://FUZZ.target.com -w subdomains.txt
   1266 
   1267 # VHOST fuzzing
   1268 ffuf -u https://target.com -H "Host: FUZZ" -w vhosts.txt
   1269 
   1270 # POST data fuzzing
   1271 ffuf -u https://target.com/login -X POST -d "user=admin&pass=FUZZ" -w passwords.txt
   1272 
   1273 # Filter by status code
   1274 ffuf -u https://target.com/FUZZ -w wordlist.txt -fc 404,403
   1275 
   1276 # Match status code
   1277 ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301
   1278 
   1279 # Filter by size
   1280 ffuf -u https://target.com/FUZZ -w wordlist.txt -fs 4242
   1281 
   1282 # Save output
   1283 ffuf -u https://target.com/FUZZ -w wordlist.txt -o results.json -of json
   1284 
   1285 # Recursive scanning
   1286 ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 2
   1287 
   1288 # Rate limiting
   1289 ffuf -u https://target.com/FUZZ -w wordlist.txt -rate 10 -t 5
   1290 
   1291 # Through proxy
   1292 ffuf -u https://target.com/FUZZ -w wordlist.txt -replay-proxy http://127.0.0.1:8080
   1293 
   1294 # Auto-calibration
   1295 ffuf -u https://target.com/FUZZ -w wordlist.txt -ac
   1296 ```
   1297 
   1298 ## Common Errors & Solutions
   1299 
   1300 - **"no wordlist defined"** — Specify a wordlist with `-w`.
   1301 - **"no target url defined"** — Specify a URL with `-u`.
   1302 - **"no FUZZ keyword found"** — Your URL or data must contain the keyword `FUZZ`.
   1303 - **High false positive rate** — Use `-ac` for auto-calibration; add filters (`-fc 404 -fs 0`); use matchers (`-mc 200`).
   1304 - **Too slow** — Increase threads (`-t 100`); use smaller wordlist first; use HEAD method (`-X HEAD`).
   1305 - **Getting blocked/rate limited** — Reduce threads (`-t 5`); add delay (`-p 1`); reduce rate (`-rate 5`); rotate User-Agent; use a proxy.
   1306 - **No results showing** — Remove filters temporarily; check if site is up; use `-v`; check matcher settings.
   1307 
   1308 ## Comparison: ffuf vs wfuzz vs gobuster
   1309 
   1310 | Feature | ffuf | wfuzz | gobuster |
   1311 |---------|------|-------|----------|
   1312 | Speed | High | Medium | High |
   1313 | Ease of Use | High | Medium | High |
   1314 | Features | High | High | Medium |
   1315 | Recursion | Yes | No | Yes |
   1316 | Multiple Keywords | Yes | Yes | No |
   1317 | Output Formats | Many | Few | Few |
   1318 | Auto-Calibration | Yes | No | No |
   1319 
   1320 ffuf is generally the best all-around choice for modern web fuzzing.
   1321 
   1322 ## Resources
   1323 
   1324 - Official repo: https://github.com/ffuf/ffuf
   1325 - Documentation: https://github.com/ffuf/ffuf/wiki
   1326 - SecLists: https://github.com/danielmiessler/SecLists
   1327 - PayloadsAllTheThings: https://github.com/swisskyrepo/PayloadsAllTheThings
   1328 
   1329 > Always ensure you have proper authorization before testing any target.