home/toolvault/web app testing/ffuf

ffuf //

Web App Testingfuzzer

Fuzz Faster U Fool: the community's speed-demon fuzzer for directories, parameters, vhosts โ€” and a must for CTF rooms where everything is FUZZ.

difficulty ยท easy
5 min
time to first win
5
guided steps
0
students started here*

HOW TO USE FFUF

Follow the steps โ€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

ffuf โ€” guided lab session
static view
step 01

Directory fuzz

ffuf -w /usr/share/wordlists/dirb/common.txt -u http://10.0.2.8/FUZZ

FUZZ keyword marks where payloads get planted.

step 02

Hide the static noise

โ€ฆ -fs 4242

Catch-all apps return identical pages; -fs filters by size.

step 03

Parameter discovery

ffuf -w params.txt -u http://site/page.php?FUZZ=1

Hidden params like debug=1 / file= are common CTF keys.

step 04

Value fuzzing (IDOR style)

ffuf -w ids.txt -u http://site/api/user?id=FUZZ

Fuzzing values โ‰  paths โ€” same tool, deeper bugs.

step 05

Subdomains at speed

ffuf -w subs.txt -u http://site/ -H 'Host: FUZZ.site'

Header fuzzing handles vhosts/subdomains too.

THE WORKFLOW AT A GLANCE

๐ŸŽฏ
FUZZ slot
path/param/vhost
๐Ÿ“š
Wordlist
payloads
๐Ÿ”
Blast
filtered
๐Ÿงน
Tune
-fs/-fc noise out
๐Ÿ•ณ๏ธ
Gold
hidden endpoint
LEARNING CURVE
easy โ€” 5 min to first win

FLAGS & SUPER-MOVES

-wwordlist
-u โ€ฆFUZZtarget + injection point
-fs / -fcfilter size / status
-Hcustom header
-recursionfollow found dirs
-raterequests/sec
-of jsonsave results

PRO TIPS

01

Filter first, conclusions second โ€” learn -fs/-fc/-fw before judging 'nothing found'.

Filter first, conclusions second โ€” learn -fs/-fc/-fw before judging 'nothing found'.

02

SecLists' discovery wordlists are ffuf's natural habitat.

SecLists' discovery wordlists are ffuf's natural habitat.

03

In HTB, always background a vhost fuzz while you work the main site.

In HTB, always background a vhost fuzz while you work the main site.

04

Compare two identical-look responses with --md for hidden differences.

Compare two identical-look responses with --md for hidden differences.

โš–๏ธ

Golden rule

Use ffuf only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
โœ๏ธ Author LDM ยท ldmhub4u@gmail.com
full guide v1 ยท v2 immersive ยท latest news
Made for learners, everywhere ยท 2026
*plausibly. verify commands with official docs.