Notes
Notes - notes.io |
ffuf -w /path/to/vhost/wordlist -u https://target -H "Host: FUZZ" -fs 4242
ffuf -w /path/to/paramnames.txt -u https://target/script.php?FUZZ=test_value -fs 4242
ffuf -w /path/to/values.txt -u https://target/script.php?valid_name=FUZZ -fc 401
ffuf -w /path/to/postdata.txt -X POST -d "username=admin&password=FUZZ" -u
https://target/login.php -fc 401
ffuf -w /path/to/wordlist -u https://target/FUZZ -maxtime 60
ffuf -w /path/to/wordlist -u https://target/FUZZ -maxtime-job 60 -recursion -recursiondepth 2
ffuf --input-cmd 'radamsa --seed $FFUF_NUM example1.txt example2.txt' -H "Content-Type:
application/json" -X POST -u https://ffuf.io.fi/FUZZ -mc all -fc 400
# Generate 1000 example payloads
radamsa -n 1000 -o %n.txt example1.txt example2.txt
ffuf --input-cmd 'cat $FFUF_NUM.txt' -H "Content-Type: application/json" -X POST -u https://ffuf.io.fi/ -mc all -fc 400
ffuf -w params.txt:PARAM -w values.txt:VAL -u https://example.org/?PARAM=VAL -mr "VAL" - c
ffuf -w entries.txt -u https://example.org/ -X POST -H "Content-Type: application/json" -d '{"name": "FUZZ", "anotherkey": "anothervalue"}' -fr "error"
ffuf -w hosts.txt -u https://example.org/ -H "Host: FUZZ" -mc 200 ffuf -w wordlist.txt -u https://example.org/FUZZ -mc all -fs 42 -c -v # Example timing based sql injection payload
ffuf -w sqli_payloads.txt -u 'https://ffuf.io.fi/api/something' -H 'Content-Type:
application/json' -d '{"id":"FUZZ"}' -mt >5000
# Example: match all, but filter out all responses of word count 7
ffuf -w wordlist.txt -u 'https://ffuf.io.fi/FUZZ' -mc all -fw 7
# Example: match all, but filter out all responses of size 42
ffuf -w wordlist.txt -u 'https://ffuf.io.fi/FUZZ' -mc all -fs 42
# Example: match all, but filter out all 400 (bad request) responses
ffuf -w wordlist.txt -u 'https://ffuf.io.fi/FUZZ' -mc all -fc 400
# Replay-proxy example
ffuf -w wordlist.txt -u 'https://ffuf.io.fi/FUZZ' -replay-proxy 'http://127.0.0.1:8080' # Proxy example
ffuf -x 'http://127.0.0.1:8080' -w wordlist.txt -u 'https://ffuf.io.fi/FUZZ' # Request body example
ffuf -w sqli_payloads.txt -u 'https://ffuf.io.fi/api/v1/users/1' -X PUT -H 'ContentType: application/json' -d '{"uid":"FUZZ"}' -X PUT
# Header example
ffuf -w wordlist.txt -u 'https://ffuf.io.fi/' -H 'FUZZ: 127.0.0.1' # Verb example
ffuf -X PATCH -w wordlist.txt -u https://ffuf.io.fi/FUZZ # Raw request example
ffuf -w wordlist.txt -request raw_req.txt # Pitchfork example
ffuf -mode pitchfork -w usernames.txt:USER -w user_ids.txt:UID -u 'https://example.org/u/UID/profile/USER'
# Multi-wordlist clusterbomb example
ffuf -mode clusterbomb -w domains.txt:DOMAIN -w wordlist.txt:WORD -u 'https://DOMAIN/WORD'
# Multi-wordlist example
ffuf -w domains.txt:DOMAIN -w wordlist.txt:WORD -u 'https://DOMAIN/WORD' # Custom FUZZ keyword example
ffuf -w wordlist.txt:MYCUSTOMKEYWORD -u 'https://ffuf.io.fi/MYCUSTOMKEYWORD' # Example
ffuf -w wordlist.txt -u 'https://ffuf.io.fi/FUZZ'
wget http://ffuf.me/wordlist/common.txt wget http://ffuf.me/wordlist/parameters.txt wget http://ffuf.me/wordlist/subdomains.txt
|
Notes.io is a web-based application for taking notes. You can take your notes and share with others people. If you like taking long notes, notes.io is designed for you. To date, over 8,000,000,000 notes created and continuing...
With notes.io;
- * You can take a note from anywhere and any device with internet connection.
- * You can share the notes in social platforms (YouTube, Facebook, Twitter, instagram etc.).
- * You can quickly share your contents without website, blog and e-mail.
- * You don't need to create any Account to share a note. As you wish you can use quick, easy and best shortened notes with sms, websites, e-mail, or messaging services (WhatsApp, iMessage, Telegram, Signal).
- * Notes.io has fabulous infrastructure design for a short link and allows you to share the note as an easy and understandable link.
Fast: Notes.io is built for speed and performance. You can take a notes quickly and browse your archive.
Easy: Notes.io doesn’t require installation. Just write and share note!
Short: Notes.io’s url just 8 character. You’ll get shorten link of your note when you want to share. (Ex: notes.io/q )
Free: Notes.io works for 12 years and has been free since the day it was started.
You immediately create your first note and start sharing with the ones you wish. If you want to contact us, you can use the following communication channels;
Email: [email protected]
Twitter: http://twitter.com/notesio
Instagram: http://instagram.com/notes.io
Facebook: http://facebook.com/notesio
Regards;
Notes.io Team