Web Application
Wfuzz
Flexible web application fuzzer for params, headers, auth, etc.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Complex injection point fuzzing beyond simple path brute force.
How
Place FUZZ markers; filter responses by code/lines/words/chars.
Why
Extremely flexible for creative web testing.
Commands & usage
wfuzz -c -z file,wordlist.txt --hc 404 https://example.com/FUZZ
wfuzz -z file,sqli.txt -d 'id=FUZZ' https://example.com/page.php
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in Web Application
ffuf
Fast web fuzzer for directories, vhosts, parameters, and more.
Gobuster
Directory/DNS/vhost brute-forcing tool written in Go.
Feroxbuster
Recursive content discovery tool with smart filtering.
dirsearch
Feature-rich web path scanner in Python.
Nuclei
Template-based vulnerability scanner with huge community template set.
Nikto
Classic web server scanner for dangerous files, misconfigs, outdated software.