Skip to content

ffuf

Fast web fuzzer written in Go

VerifiedPentesting· Content DiscoveryBeginnerMITOpen sourceEntry revised 19 Jan 2026
  • Linux
  • macOS
  • Windows
  • Kali
  • Parrot
  • Arch
  • Docker
  • Source

Overview

9 commands documented

ffuf drives a list of values into a placeable FUZZ position in a URL, header, body or cookie, and reports responses that differ from the noise. It is commonly used for content discovery and for controlled input testing on applications you are authorized to assess.

Its filtering flags are the reason people reach for it: after a run you can throw away everything that matched a size, status code, word count, regex or line count, which is what makes a 100k-word list survivable.

Supported platforms

8

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

fuzzing, content discovery, directories, http, vhosts

Dataset entry

ffuf.ts

Reviewed 2026-01-19

Installation

Grouped by platform. Elevation requirements are marked per method.

Official release archive

RecommendedreleaseOfficial

Grab the Windows .zip from the repository's releases page and add the folder to PATH.

Open official source

Package availability follows your distribution and enabled repositories. Entry revised 19 Jan 2026 — confirm the current release on the project's own download page.

Commands

9 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Content discovery with one FUZZ position

bash

Replaces FUZZ in the URL with each word of the list and prints responses that pass the filters.

ffuf -u http://192.0.2.20/FUZZ -w /usr/share/wordlists/secLists/Discovery/Web-Content/common.txt
  • Run only against systems you are authorized to test.

Notes

  • The default filters out nothing but responses with an empty size, status 0 and the same size as `-recalibrate`'s baseline request when enabled.

02Filter out the noise

bash

Keep only interesting responses by status code, and drop a known soft-404 size.

ffuf -u http://192.0.2.20/FUZZ -w wordlist.txt -mc 200,204,301,302,307,401,403 -sc 404

Notes

  • `-mc` = match codes, `-sc` = suppress codes. `-fc` / `-fs` / `-fw` / `-fl` / `-fr` are the matching counterparts for code, size, words, lines and regex.

03Auto-calibrate a soft-404 baseline

bash

Sends a probe request per word and discards responses that look identical to the 'not found' page — the single most useful flag on noisy applications.

ffuf -u http://192.0.2.20/FUZZ -w wordlist.txt -recalibrate

Notes

  • Use `-calibrated-lines 5` when the baseline size varies, and confirm the calibration result: a site returning identical sizes for everything will hide real paths.

04Virtual host enumeration

bash

Drives the Host header instead of the path to find names that the same IP serves.

ffuf -u http://192.0.2.20 -H 'Host: FUZZ.internal' -w hosts.txt -fs 0

Notes

  • Many front ends answer 200 for unknown hosts; always compare against a deliberately invalid host.

05Authenticated run with a cookie and rate limit

bash

Reuses a session and throttles requests so a WAF or a shared staging box stays usable.

ffuf -u https://app.internal/FUZZ -w wordlist.txt -b 'session=abc123' -t 20 -p 0.2 -maxtime 10m
  • Session cookies expire mid-run. Watch for a wall of 302s to /login and treat them as a failed run, not as findings.

Notes

  • `-t` sets threads, `-p` adds a per-request pause, `-maxtime` bounds the run.

06Fuzz a POST parameter

bash

Places the value inside the request body with multiple FUZZ positions.

ffuf -u https://app.internal/search -X POST -d 'q=FUZZ&page=FUZZ2' -w words.txt -w pages.txt:FUZZ2

Notes

  • Multiple `-w` flags pair a wordlist with a named position. Keep total requests in mind: it is list A × list B.

07Fuzz an existing request captured by a proxy

bash

Load a raw request file so headers, tokens and body are preserved exactly as the browser sent them.

ffuf -request req.txt -request-proto http -w wordlist.txt

Notes

  • Paste the request from Burp's 'Copy to file' or a raw HTTP export. Never paste requests containing live user tokens into shared notes.

08Transform words on the fly

bash

The replacer applies URL encoding, case changes or templating to each word without a second list.

ffuf -u http://192.0.2.20/FUZZ -w list.txt -replacer urlencode

Example output

Illustrative only — real output depends on the target, version and your position on the network.

admin → admin%20FUZZ-style payloads with url-encoding applied

Notes

  • Chain several with `-replacer=urleset,append`. `urleset` in particular bypasses naive 'decode once' normalisation checks.

09Save results for reporting

bash

Writes machine-readable output you can revisit without re-running the scan.

ffuf -u http://192.0.2.20/FUZZ -w wordlist.txt -o findings.json -of json

Notes

  • Supported formats include json, ejson, md, html, csv, xml and md (default json when `-o` has no extension hint).

Worked examples

Sequences of commands in the order they are used, with what you should expect to learn from each.

Enumerate an admin surface without flooding the app

A staging app is in scope, and it returns a 200 page for every unknown path.

  1. 1

    Establish the soft-404 baseline

    ffuf -u https://staging.internal/FUZZ -w /dev/null -calibrate 2>/dev/null || true
  2. 2

    Run with filters, threads and pause tuned for a shared system

    ffuf -u https://staging.internal/FUZZ -w common.txt -mc 200,301,302,401,403 -fs 1473 -t 10 -p 0.1 -o ffuf-admin.json
  3. 3

    Confirm each hit manually

    curl -sk -o /dev/null -w '%{http_code} %{size_download}\n' https://staging.internal/backup.sql

A short list of candidates, each verified by hand before anything reaches a report — never trust fuzz output alone.

What it is used for

  • Content and directory discovery

    Find exposed paths, backups and panels on an in-scope web host.

  • Virtual host review

    Discover internal names bound to one IP.

  • Parameter behaviour testing

    Observe how an endpoint reacts to controlled inputs in a lab.

  • API route enumeration

    Compare documented and undeclared routes in a staging tenant.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

Thousands of results, all with status 200 and the same lengthCause 1/4

Possible causes

  • The application serves a catch-all route (soft 404).

Usual fix

Identify the baseline response size and suppress it (`-fs <size>`), or use `-recalibrate`. Add `-max-candidates` when exploring a very large list.

"error: unknown shorthand flag" after upgradingCause 2/4

Possible causes

  • Flags moved between ffuf v1 and v2 releases.

Usual fix

Check `ffuf -h` for the installed version, and pin the release in reusable scripts instead of following blog-post syntax.

Every request returns 429 or a WAF block pageCause 3/4

Possible causes

  • Thread count exceeded the rate limit or the WAF flagged the pattern.

Usual fix

Reduce `-t`, add `-p`, shrink the list, and check the scope/rules of engagement — deliberately evading a WAF is out of scope for most assessments.

Runs finish with 0 results on HTTPS targetsCause 4/4

Possible causes

  • TLS verification failing silently, or a proxy configured in the environment.

Usual fix

Add `-s` for silence-free output while testing, and set `-x` only when you intend to route through a proxy.

ffuf -u https://app.internal/FUZZ -w list.txt -x http://127.0.0.1:8080 -k

Tips

  • Sort findings by response size variance rather than by status: a path that differs in length from the baseline is usually real.
  • Keep wordlists small and iterate. `common.txt` then `raft-small-words` beats one 4M-line list.
  • Persist `-o file.json` every run; you will want to re-filter old results instead of re-fuzzing an application.
  • Use `-e .php,.html,.json` for extension fuzzing and `-s` to remove the progress bar when piping output.

Alternatives & comparisons

Not documented yet: feroxbuster. Request an entry and it will link up automatically.Request a tool

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Pentesting

Looking for alternatives?

Gobuster cover adjacent parts of the same job.

Compare side by side