-fs or -fw to filter noise, -mc to whitelist status codes. Run with -t 50 threads by default; back off if the target rate-limits.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
-fs or -fw to filter noise, -mc to whitelist status codes. Run with -t 50 threads by default; back off if the target rate-limits.
# Directory
ffuf -u http://$IP/FUZZ -w ~/tools/wordlists/seclists/Discovery/Web-Content/raft-medium-directories.txt -mc 200,301,302,403 -t 50
# Files with extensions
ffuf -u http://$IP/FUZZ -w ~/tools/wordlists/seclists/Discovery/Web-Content/raft-medium-files.txt -e .php,.txt,.html,.bak
# vHost
ffuf -u http://$IP/ -H "Host: FUZZ.$DOMAIN" -w ~/tools/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt -mc 200 -fs $SIZE
# POST
ffuf -u http://$IP/login -X POST -d "user=FUZZ&pass=test" -w users.txt -mc 200
# Params
ffuf -u http://$IP/page?FUZZ=test -w ~/tools/wordlists/seclists/Discovery/Web-Content/burp-parameter-names.txt -mc 200 -fs $SIZE
-mc 200,301,302 match codes
-fc 404 filter code
-fs <size> filter size
-fw <words> filter words
-t 50 threads
-rate 100 rate limit
-o out.json output
-c colorize