Official release archive
RecommendedreleaseOfficialGrab the Windows .zip from the repository's releases page and add the folder to PATH.
Open official sourceFast web fuzzer written in Go
ffuf drives a list of values into a placeable FUZZ position in a URL, header, body or cookie, and reports responses that differ from the noise. It is commonly used for content discovery and for controlled input testing on applications you are authorized to assess.
Its filtering flags are the reason people reach for it: after a run you can throw away everything that matched a size, status code, word count, regex or line count, which is what makes a 100k-word list survivable.
Supported platforms
8
Documented install or usage guidance
Learning curve
beginner
Difficulty of becoming productive, not of the underlying theory
Tags
fuzzing, content discovery, directories, http, vhosts
Dataset entry
ffuf.ts
Reviewed 2026-01-19
Grouped by platform. Elevation requirements are marked per method.
Grab the Windows .zip from the repository's releases page and add the folder to PATH.
Open official sourcebrew install ffuf
Needs elevated privileges (sudo / Administrator).
sudo apt update
sudo apt install ffuf
Builds a current binary into $GOPATH/bin.
go install github.com/ffuf/ffuf/v2@latest
git clone https://github.com/ffuf/ffuf
cd ffuf && go build -o ffuf .
Package availability follows your distribution and enabled repositories. Entry revised 19 Jan 2026 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
Replaces FUZZ in the URL with each word of the list and prints responses that pass the filters.
ffuf -u http://192.0.2.20/FUZZ -w /usr/share/wordlists/secLists/Discovery/Web-Content/common.txt
Notes
Keep only interesting responses by status code, and drop a known soft-404 size.
ffuf -u http://192.0.2.20/FUZZ -w wordlist.txt -mc 200,204,301,302,307,401,403 -sc 404
Notes
Sends a probe request per word and discards responses that look identical to the 'not found' page — the single most useful flag on noisy applications.
ffuf -u http://192.0.2.20/FUZZ -w wordlist.txt -recalibrate
Notes
Drives the Host header instead of the path to find names that the same IP serves.
ffuf -u http://192.0.2.20 -H 'Host: FUZZ.internal' -w hosts.txt -fs 0
Notes
Reuses a session and throttles requests so a WAF or a shared staging box stays usable.
ffuf -u https://app.internal/FUZZ -w wordlist.txt -b 'session=abc123' -t 20 -p 0.2 -maxtime 10m
Notes
Places the value inside the request body with multiple FUZZ positions.
ffuf -u https://app.internal/search -X POST -d 'q=FUZZ&page=FUZZ2' -w words.txt -w pages.txt:FUZZ2
Notes
Load a raw request file so headers, tokens and body are preserved exactly as the browser sent them.
ffuf -request req.txt -request-proto http -w wordlist.txt
Notes
The replacer applies URL encoding, case changes or templating to each word without a second list.
ffuf -u http://192.0.2.20/FUZZ -w list.txt -replacer urlencode
Example output
Illustrative only — real output depends on the target, version and your position on the network.
admin → admin%20FUZZ-style payloads with url-encoding applied
Notes
Writes machine-readable output you can revisit without re-running the scan.
ffuf -u http://192.0.2.20/FUZZ -w wordlist.txt -o findings.json -of json
Notes
Sequences of commands in the order they are used, with what you should expect to learn from each.
A staging app is in scope, and it returns a 200 page for every unknown path.
Establish the soft-404 baseline
ffuf -u https://staging.internal/FUZZ -w /dev/null -calibrate 2>/dev/null || true
Run with filters, threads and pause tuned for a shared system
ffuf -u https://staging.internal/FUZZ -w common.txt -mc 200,301,302,401,403 -fs 1473 -t 10 -p 0.1 -o ffuf-admin.json
Confirm each hit manually
curl -sk -o /dev/null -w '%{http_code} %{size_download}\n' https://staging.internal/backup.sqlA short list of candidates, each verified by hand before anything reaches a report — never trust fuzz output alone.
Find exposed paths, backups and panels on an in-scope web host.
Discover internal names bound to one IP.
Observe how an endpoint reacts to controlled inputs in a lab.
Compare documented and undeclared routes in a staging tenant.
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
Identify the baseline response size and suppress it (`-fs <size>`), or use `-recalibrate`. Add `-max-candidates` when exploring a very large list.
Possible causes
Usual fix
Check `ffuf -h` for the installed version, and pin the release in reusable scripts instead of following blog-post syntax.
Possible causes
Usual fix
Reduce `-t`, add `-p`, shrink the list, and check the scope/rules of engagement — deliberately evading a WAF is out of scope for most assessments.
Possible causes
Usual fix
Add `-s` for silence-free output while testing, and set `-x` only when you intend to route through a proxy.
ffuf -u https://app.internal/FUZZ -w list.txt -x http://127.0.0.1:8080 -k
Not documented yet: feroxbuster. Request an entry and it will link up automatically.Request a tool
Side-by-side
Where to verify anything on this page. External links open in a new tab.
Gobuster cover adjacent parts of the same job.