Fuzz web paths, parameters, and virtual hosts with ffuf to surface hidden attack surface
Probe for hidden routes, parameter behaviors, and vhost exposures fast, before you spend time manually poking at the wrong surface.
Prerequisites
ffuf binary, reachable target URL, wordlists, network access, operator-approved test scope
Installation
Requirements and caveats from upstream:
- Ffuf depends on Go 1.16 or greater.
- You can also practise your ffuf scans against a live host with different lessons and use cases either locally by using the docker container https://github.com/adamtlangley/ffufme or against the live hosted version at...
Basic usage or getting-started notes:
Download a prebuilt binary from releases page, unpack and run!
Source: https://github.com/ffuf/ffuf
Extracted from upstream docs: https://raw.githubusercontent.com/ffuf/ffuf/HEAD/README.md