<aside> ⌛


Fuzzing

The term fuzzing refers to a testing technique that sends various types of user input to a certain interface to study how it would react

Wordlists

To determine which pages exist, we should have a wordlist containing commonly used words for web directories and pages, very similar to a Password Dictionary Attack,


1- Directory Fuzzing

ffuf -w /usr/share/seclists/Discovery/web-content/directory-list:FUZZ

ffuf -w /usr/share/seclists/Discovery/Web-Content/direc....:FUZZ -u <http://IP-SERVER>:PORT/FUZZ

2- Page Fuzzing

Before Page Fuzzing we want to know which Exetnsion we will use, lile .html . php .asp .. etc so we will make a Extension Fuzzing First like → ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u <http://83.136.249.93:50252/FUZZ>

and the results shows that exetenstions is .php phps

image.png

so the command for page Fuzzing is

└─# ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u [<http://83.136.249.93:50252/blog/FUZZ.php>](<http://83.136.249.93:50252/blog/FUZZ.php>)

3- Recursive Fuzzing

In ffuf, we can enable recursive scanning with the -recursion flag, and we can specify the depth with the -recursion-depth flag. If we specify -recursion-depth 1, it will only fuzz the main directories and their direct sub-directories. If any sub-sub-directories are identified (like /login/user, it will not fuzz them for pages). When using recursion in ffuf, we can specify our extension with -e .php

└─# ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u [<http://83.136.249.93:50252/blog/FUZZ>](<http://83.136.249.93:50252/blog/FUZZ>) -recursion -recursion-depth 1 -v -e .php -ic