All tools

Web Application

Wfuzz

Flexible web application fuzzer for params, headers, auth, etc.

intermediate
Linux
Enumeration
Exploitation

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Complex injection point fuzzing beyond simple path brute force.

How

Place FUZZ markers; filter responses by code/lines/words/chars.

Why

Extremely flexible for creative web testing.

Commands & usage

wfuzz -c -z file,wordlist.txt --hc 404 https://example.com/FUZZ
wfuzz -z file,sqli.txt -d 'id=FUZZ' https://example.com/page.php

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

fuzzing
web

Related in Web Application