Wfuzz is a tool designed for bruteforcing Web Applications, it can be used for finding resources not linked (directories, servlets, scripts, etc), bruteforce GET and POST parameters for checking different kind of injections (SQL, XSS, LDAP,etc), bruteforce Forms parameters (User/Password), Fuzzing,etc.
The tool is based on dictionaries and ranges, you choose where you want to bruteforce just by replacing the part of the URL or the POST by the keyword FUZZ.
It’s very flexible, here are some functionalities:
- Recursion (When doing directory bruteforce)
- Post data bruteforcing
- Output to HTML (easy for just clicking the links and checking the page, even with postdata!!)
- Colored output on all systems
- Hide results by return code, word numbers, line numbers, etc.
- URL encoding
- Cookies
- Multithreading
- Proxy support
- All parameters bruteforcing (POST and GET)
- Dictionaries tailored for known applications (Weblogic, Iplanet, Tomcat, Domino, Oracle 9i, Vignette, Coldfusion and many more.
Example:
wfuzz.py -c -z file -f commons.txt --hc 404 --html http://www.mysite.com/FUZZ
This will bruteforce the site http://www.mysite.com/FUZZ in search of resources (directories, scripts, files,etc), it will hide from the output the return code 404 (for easy reading the results), it will use the dictionary commons.txt for the bruteforce.
It was created to facilitate the task in Web Applications assessments, it’s a tool by pentesters for pentesters.
You can download Wfuzz here:
Wfuzz 1.1 – Win32
Wfuzz 1.1 – Unix
Or read more here.
Stored in: Hacking Tools, Web Hacking
Related Posts:
- Wfuzz v1.4 Released for Download – Bruteforcing & Fuzzing Web Applications
- Keep on Fuzzing! Advice
- FRHACK OS v1 alpha1 – Pentesting/Security LiveCD
- SWFIntruder – Analysis and Security Testing of Flash Applications
- Sprajax – An Open Source AJAX Security Scanner
- SWFScan – Free Flash Application Security Scanner
| 9,008 views |



Nice tool… really like it.. very quick an easy to use…
added it to my favourites list.
it’s a great tool, but mostly I like the fact that it can use proxy support, and threading which is a must at bruteforcing tools…
nice tool.
ohh yeah…. multi threading is a must in such tools to make the attack faster…
i like the nice formatted output too..
not to mention that time means money in such a critical situation… meaning in the moments when the tools isn’t used for pen-testing
yes you are right backbone…
these tools are essential for pen testing jobs as most of the times (atleast for me), clients try not to spend much money on them and expect thorough testing… and its only possible by using good pen testing tools.
I can’t seem to get wfuzz to work correctly. Whenever I try to run it I get a command not recognized error. I have installed pycurl, but it doesn’t seem to make a difference. If I have it output to an HTML file, the contents only say bash command not found. What am I doing wrong?
it just pops up real quick, then closes, why?
Can someone point me documentations/manual for this tool?