Introduction to web fuzzing techniques. In this video we explore the key features of popular fuzzing tools wfuzz and ffuf using Metasploitable3 as a test case. We compare the tools in terms of functionality, performance and computational cost to find out which is best for general web fuzzing? (answer.. it's ffuf 😆) - Hope you enjoy 🙂
Note: @codingo and @InsiderPhD both did excellent deep dives into ffuf, covering wayyy more detail than I do here so check them out for more deets! • How to Master FFUF for Bug Bounties a... , • How to use ffuf - Hacker Toolbox
↢Social Media↣
Twitter: / _cryptocat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: / cryptocat
Reddit: / _cryptocat23
YouTube: / cryptocat23
Twitch: / cryptocat23
↢Resources↣
ffuf: https://github.com/ffuf/ffuf
wfuzz: https://wfuzz.readthedocs.io/en/latest
ffuf vs wfuzz: https://www.doria.fi/handle/10024/181265
seclists: https://github.com/danielmiessler/Sec...
wordlists: https://gowthams.gitbook.io/bughunter...
crackstation passwords: https://crackstation.net/crackstation...
ffuf cheatsheet: https://codingo.io/tools/ffuf/bounty/..., https://www.tsustyle.com/cheatsheets/...
wfuzz cheatsheet: https://book.hacktricks.xyz/pentestin...
Portswigger exercise: https://portswigger.net/web-security/...
↢Chapters↣
Start - 0:00
cheatsheet/wordlists - 0:50
wfuzz and ffuf intro - 2:11
wfuzz vs ffuf comparison - 7:30
fuzz directories and files - 14:20
fuzz header/cookie/post data - 18:35
fuzz credentials (portswigger web security academy) - 23:35