Skip to content

Fuzzing

Fuzzing is a technique used to discover paths and resources hidden in a web server through brute force attacks. The objective is to find hidden resources that could be used to obtain unauthorized access to the server.

Gobuster

Description

Gobuster is a tool used to brute-force:

  • URIs (directories and files) in web sites.
  • DNS subdomains (with wildcard support).
  • Virtual Host names on target web servers.
  • Open Amazon S3 buckets
  • Open Google Cloud buckets
  • TFTP servers

One of the main advantages of Gobuster is the speed that it has in discovering content.

Parameters

ParameterDescription
dirUse directory or file enumeration mode
-u Specify the URL to fuzz
-w Specify the wordlist to use
-t Number of parallel threads
–add-slashAdds a / at the end of the path
-b Exclude the specified status code from results
-s Show only the specified status code
-x Add extensions to the end of the path

Examples

  • Basic fuzzing:
gobuster dir -u https://domain.com -w <wordlist> -t 200

  • Add a / at the end of each path and exclude certain status codes:
gobuster dir -u https://domain.com -w <wordlist> -t 200 -b 403,404

  • Test specific extensions:
gobuster dir -u https://domain.com -w <wordlist> -t 200 -b 403,404 -x php,html,txt

  • Show only status code 200:
gobuster dir -u https://domain.com -w <wordlist> -t 200 -s 200 -b '' -x php,html,txt

Wfuzz

Description

Wfuzz has been created to facilitate the task in web applications assessments and it is based on a simple concept: it replaces any reference to the FUZZ keyword by the value of a given payload.

Parameters

ParameterDescription
-cDisplay output with colors
-t Number of parallel threads
-w Specifies the wordlist to use
–hc=Excludes the specified status code from being shown
-LFollow redirects
-z ,Allows specifying custom payloads, for example for file extensions

Examples

  • Basic fuzzing:
wfuzz -c -t 200 -w <wordlist> https://domain.com/FUZZ

  • Exclude status codes 404 and 403:
wfuzz -c --hc=404,403 -t 200 -w <wordlist> https://domain.com/FUZZ

  • Test specific extensions:
wfuzz -c --hc=404,403 -t 200 -w <wordlist> -z list,html-txt-php https://domain.com/FUZZ.FUZ2Z

Ffuf

Description

Ffuf is a fast web fuzzer written in Go.

Parameters

ParameterDescription
-uTarget URL
-w Wordlist file path and (optional) keyword separated by colon. eg. ‘/path/to/wordlist:KEYWORD’
-cColorize output.
-vVerbose output, printing full URL and redirect location (if any) with the results.
-mcMatch HTTP status codes, or “all” for everything.

Examples

  • Basic fuzzing:
ffuf -c -t 200 -w \<wordlist\> -u https://domain.com/FUZZ

  • Show only status code 200:
ffuf -c -t 200 -w \<wordlist\> -u https://domain.com/FUZZ --mc=200