
Ffuf Web Fuzzing
- 74 installs
- 475 repo stars
- Updated July 14, 2026
- trailofbits/skills-curated
Helps with ai & agent building tasks during AI-assisted development.
About
ffuf-web-fuzzing is a Claude Code skill for ai & agent building. It helps solo builders move faster with AI-assisted coding.
- ffuf-web-fuzzing
- AI & Agent Building
- AI-coding skill
Ffuf Web Fuzzing by the numbers
- 74 all-time installs (skills.sh)
- +6 installs in the week ending Aug 5, 2026 (Skillselion tracking)
- Ranked #5,535 of 16,546 AI & Agent Building skills by installs in the Skillselion catalog
- Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/trailofbits/skills-curated --skill ffuf-web-fuzzingAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 74 |
|---|---|
| repo stars | ★ 475 |
| Last updated | July 14, 2026 |
| Repository | trailofbits/skills-curated ↗ |
What it does
Helps with ai & agent building tasks during AI-assisted development.
Files
FFUF Web Fuzzing
Guidance for using ffuf (Fuzz Faster U Fool) effectively during authorized penetration testing.
Prerequisites
ffuf must be installed: brew install ffuf (macOS) or go install github.com/ffuf/ffuf/v2@latest
When to Use
- Running directory, file, or subdomain discovery against web targets
- Fuzzing API endpoints, parameters, or POST data
- Authenticated fuzzing with raw HTTP requests
- Analyzing ffuf JSON output for anomalies and interesting findings
- Building fuzzing strategies (wordlist selection, filtering, rate limiting)
- IDOR testing with authenticated sessions
When NOT to Use
- Target system is not in scope or authorization is unclear
- Passive reconnaissance is more appropriate (use OSINT tools instead)
- The target is a production system and rate limiting hasn't been configured
- You need a full vulnerability scanner (use Burp Suite, Nuclei, etc.)
- Testing for logic flaws that require multi-step interaction
Rationalizations to Reject
- "Auto-calibration is optional" --
-acis mandatory. Without it, results are buried in false positives and analysis is wasted effort. - "More threads = faster results" -- Hammering a target with
-t 200triggers WAFs, gets you blocked, and may crash staging environments. Start with-t 10 -rate 2for production targets. - "I'll filter later" -- Set up filtering before the scan. Running a 220k wordlist without filters and then trying to grep through the noise is backwards.
- "The default wordlist is fine" -- Wordlist selection is the most important decision. A generic wordlist misses technology-specific paths. See references/wordlists.md.
- "Raw requests are too much work" -- For authenticated fuzzing,
--request req.txtis simpler and more reliable than chaining-Hand-bflags. Capture once, fuzz many times.
Critical Rules
1. Always use `-ac` (auto-calibration) unless you have a specific, documented reason not to 2. Always save output with -o results.json for later analysis 3. Rate limit production targets with -rate and -t flags 4. Use `--request` for auth -- raw request files beat command-line header chains 5. Confirm authorization first -- before running any scan, verify the user has written permission for the target. Ask if unclear.
Core Concepts
The FUZZ Keyword
# In URL path
ffuf -w wordlist.txt -u https://target.com/FUZZ -ac
# In headers
ffuf -w wordlist.txt -u https://target.com -H "Host: FUZZ.target.com" -ac
# In POST body
ffuf -w wordlist.txt -X POST -d "user=admin&pass=FUZZ" -u https://target.com/login -ac
# Multiple positions with custom keywords
ffuf -w endpoints.txt:EP -w ids.txt:ID -u https://target.com/EP/ID -mode pitchfork -acAuto-Calibration
-ac automatically detects and filters repetitive false-positive responses. It adapts to the target's specific behavior and removes noise from dynamic content.
ffuf -w wordlist.txt -u https://target.com/FUZZ -ac # Standard
ffuf -w wordlist.txt -u https://target.com/FUZZ -ach # Per-host (multi-host scans)
ffuf -w wordlist.txt -u https://target.com/FUZZ -acc "404" # Custom calibration stringCommon Patterns
Directory Discovery
ffuf -w /opt/SecLists/Discovery/Web-Content/raft-large-directories.txt \
-u https://target.com/FUZZ -e .php,.html,.txt,.bak \
-ac -c -v -o results.jsonSubdomain Enumeration
ffuf -w /opt/SecLists/Discovery/DNS/subdomains-top1million-5000.txt \
-u https://FUZZ.target.com -ac -c -v -o results.jsonAPI Endpoint Discovery
ffuf -w /opt/SecLists/Discovery/Web-Content/api/api-endpoints.txt \
-u https://api.target.com/v1/FUZZ \
-H "Authorization: Bearer YOUR_TOKEN_HERE" -mc 200,201 -ac -cAuthenticated Fuzzing with Raw Requests
Capture a full authenticated request, save to req.txt, insert FUZZ:
POST /api/v1/users/FUZZ HTTP/1.1
Host: target.com
Authorization: Bearer YOUR_TOKEN_HERE
Cookie: session=YOUR_SESSION_ID
Content-Type: application/json
{"action":"view","id":"1"}ffuf --request req.txt -w wordlist.txt -ac -o results.jsonSee references/request-templates.md for pre-built templates covering bearer tokens, session cookies, API keys, and GraphQL.
Authenticated Fuzzing: Agent Workflow
Authenticated fuzzing requires real credentials that the agent cannot obtain independently. When the user asks for authenticated fuzzing:
1. Ask the user to provide ONE of:
- A raw HTTP request file (
req.txt) with auth headers already included - A curl command from browser DevTools (convert it to
req.txtformat) - Individual credentials (Bearer token, session cookie, API key)
2. If given a curl command, convert it to raw HTTP request format and write to req.txt 3. If given individual credentials, use a template from references/request-templates.md and substitute real values 4. Never fabricate or guess authentication tokens
IDOR Testing
ffuf --request req.txt -w <(seq 1 10000) -ac -mc 200 -o idor_results.jsonRate Limiting
| Environment | Flags | Notes |
|---|---|---|
| Production (stealth) | -rate 2 -t 10 | Avoid WAF triggers |
| Production (normal) | -rate 10 -t 20 | Balanced |
| Staging/Dev | -rate 50 -t 40 | Faster |
| Local/Lab | No limit, -t 100 | Maximum speed |
Analyzing Results
Save output as JSON (-o results.json), then read the file and focus on:
- Anomalous status codes -- anything other than the baseline 404/403
- Size outliers -- responses significantly larger or smaller than average
- Interesting keywords in URLs -- admin, api, backup, config, .git, .env
- Timing anomalies -- slow responses may indicate SQL injection or heavy processing
- Follow-up targets -- interesting findings warrant deeper fuzzing
Use -fs to filter by response size and -fc to filter by status code when auto-calibration isn't sufficient. Run ffuf -h for the full list of match/filter flags.
References
- Wordlist selection guide -- recommended SecLists by scenario
- Authenticated request templates -- pre-built req.txt for bearer tokens, cookies, API keys
- ffuf official docs
- SecLists
Authenticated Request Templates
Pre-built req.txt templates for common authenticated fuzzing scenarios. Save the template, replace placeholders with real values, insert FUZZ where needed.
Bearer Token (JWT / OAuth)
GET /api/v1/users/FUZZ HTTP/1.1
Host: api.target.com
Authorization: Bearer YOUR_TOKEN_HERE
Accept: application/json
Content-Type: application/jsonffuf --request req.txt -w wordlist.txt -ac -mc 200,201 -o results.jsonSession Cookie + CSRF Token
POST /api/account/update HTTP/1.1
Host: app.target.com
Cookie: sessionid=YOUR_SESSION_ID; csrftoken=YOUR_CSRF_TOKEN
X-CSRF-Token: YOUR_CSRF_TOKEN
Content-Type: application/x-www-form-urlencoded
field=FUZZ&action=updateffuf --request req.txt -w payloads.txt -ac -fc 403 -o results.jsonAPI Key Header
GET /v2/data/FUZZ HTTP/1.1
Host: api.target.com
X-API-Key: YOUR_API_KEY_HERE
Accept: application/jsonffuf --request req.txt -w endpoints.txt -ac -mc 200 -o results.jsonPOST JSON with Auth
POST /api/v1/query HTTP/1.1
Host: api.target.com
Authorization: Bearer YOUR_TOKEN_HERE
Content-Type: application/json
Accept: application/json
{"query":"FUZZ","limit":100,"offset":0}ffuf --request req.txt -w sqli-payloads.txt -ac -fr "error" -o results.jsonMultiple FUZZ Points (Custom Keywords)
GET /api/v1/users/USER_ID/documents/DOC_ID HTTP/1.1
Host: api.target.com
Authorization: Bearer YOUR_TOKEN_HERE
Accept: application/jsonffuf --request req.txt \
-w user_ids.txt:USER_ID \
-w doc_ids.txt:DOC_ID \
-mode pitchfork \
-ac -mc 200 \
-o idor_results.jsonGraphQL Query
POST /graphql HTTP/1.1
Host: api.target.com
Authorization: Bearer YOUR_TOKEN_HERE
Content-Type: application/json
Accept: application/json
{"query":"query { user(id: \"FUZZ\") { id username email role } }","variables":{}}ffuf --request req.txt -w user-ids.txt -ac -mc 200 -mr '"email"' -o results.jsonHow to Capture Your Own Request
From Burp Suite
1. Intercept the authenticated request 2. Right-click > "Copy to file" > save as req.txt 3. Replace the fuzz target with FUZZ
From Browser DevTools
1. Open DevTools (F12) > Network tab 2. Perform the authenticated action 3. Right-click the request > Copy > Copy as cURL 4. Convert to raw HTTP format, insert FUZZ
From a curl command
# If you have:
curl 'https://api.target.com/users/123' -H 'Authorization: Bearer TOKEN'
# Convert to:
GET /users/FUZZ HTTP/1.1
Host: api.target.com
Authorization: Bearer TOKENTips
- ffuf adjusts
Content-Lengthautomatically - Use custom keywords (
USER_ID,DOC_ID) with-w wordlist.txt:KEYWORDfor multiple fuzz points - Test your
req.txtwith a single-value wordlist first to verify it works - Have a token refresh strategy ready for short-lived tokens
- Default protocol is HTTPS; use
-request-proto httpfor HTTP-only targets
Wordlist Selection Guide
Choose wordlists based on the target stack and engagement scope. All paths are relative to your SecLists installation directory.
By Scenario
Directory and File Discovery
| Scope | Wordlist | Entries | When to use |
|---|---|---|---|
| Quick scan | Discovery/Web-Content/common.txt | ~4.6k | Initial recon, time-limited engagements |
| Standard | Discovery/Web-Content/directory-list-2.3-medium.txt | ~220k | Default for most engagements |
| Thorough | Discovery/Web-Content/directory-list-2.3-big.txt | ~1.2M | High-value targets, long engagements |
| Raft (dirs) | Discovery/Web-Content/raft-large-directories.txt | - | Alternative to directory-list, good coverage |
| Raft (files) | Discovery/Web-Content/raft-large-files.txt | - | Focused on file discovery |
API Testing
| Wordlist | When to use |
|---|---|
Discovery/Web-Content/api/api-endpoints.txt | REST API endpoint discovery |
Discovery/Web-Content/common-api-endpoints-mazen160.txt | Broader API path fuzzing |
Discovery/Web-Content/swagger-parameters.txt | Finding Swagger/OpenAPI docs |
Subdomain Discovery
| Wordlist | Entries | When to use |
|---|---|---|
Discovery/DNS/subdomains-top1million-5000.txt | 5k | Quick subdomain check |
Discovery/DNS/subdomains-top1million-20000.txt | 20k | Standard engagement |
Discovery/DNS/subdomains-top1million-110000.txt | 110k | Thorough enumeration |
Discovery/DNS/namelist.txt | - | Combined/alternative list |
Parameter Names
| Wordlist | When to use |
|---|---|
Discovery/Web-Content/burp-parameter-names.txt | GET/POST parameter discovery |
Discovery/Web-Content/raft-large-words.txt | Broader parameter fuzzing |
Backup and Config Files
| Wordlist | When to use |
|---|---|
Discovery/Web-Content/backup-files-only.txt | Finding .bak, .old, .save files |
Discovery/Web-Content/Common-DB-Backups.txt | Database dump discovery |
Technology-Specific
| Wordlist | Stack |
|---|---|
Discovery/Web-Content/PHP.fuzz.txt | PHP applications |
Discovery/Web-Content/IIS.fuzz.txt | ASP/ASP.NET on IIS |
Discovery/Web-Content/Apache.fuzz.txt | Apache web servers |
Discovery/Web-Content/git-head-potential-file-exposure.txt | Git repo exposure |
File Extensions by Technology
Add with -e flag. Match extensions to the target stack.
| Stack | Extensions |
|---|---|
| PHP | .php .php3 .php4 .php5 .phtml .phps |
| ASP/ASP.NET | .asp .aspx .ashx .asmx .axd |
| JSP/Java | .jsp .jspx .jsw .jsv .jspf |
| Python | .py .pyc .pyo |
| Ruby | .rb .rhtml |
| Node.js | .js .json |
| Backup/Interesting | .bak .backup .old .save .tmp .swp .git .env .config .conf .log .sql .db .sqlite |