
ffuf
Fast open-source web fuzzer written in Go for directory, virtual-host and parameter discovery during authorised web assessments.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 1 October 2026
- Links
- GitHub
What it is
ffuf (Fuzz Faster U Fool) is a fast, open-source web fuzzer written in Go. Testers place the FUZZ keyword in URLs, headers or request bodies and drive wordlists against those positions to discover hidden content and inputs. It is widely used for web application enumeration and is covered as a dedicated module in Hack The Box Academy’s Basic Toolset path.
What it helps with
- Discovering directories, files and endpoints with wordlist-driven path fuzzing.
- Finding virtual hosts and Host-header targets when DNS records are incomplete.
- Fuzzing GET and POST parameters, including JSON bodies and multi-keyword modes.
- Filtering and matching on status codes, size, words, lines, regex and timing.
- Using recursion, rate limits, proxies, configuration files and interactive filter tuning mid-scan.
- Exporting results to JSON, CSV, HTML and related formats for engagement notes.
Who it's for
Penetration testers, bug bounty researchers and web application security engineers who need fast, flexible content and parameter discovery on targets they are authorised to test.
Worth knowing
Use ffuf only against systems you are explicitly authorised to assess. Aggressive fuzzing can generate high request volume and may trigger rate limits or defensive controls. ffuf is free under the MIT Licence; install via official GitHub releases, package managers or Go. Official docs and examples live in the ffuf wiki. Attribution: product framing from the ffuf/ffuf README and wiki; licence from the repository licence file.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.