Subdomain Enumeration using FFUF
To perform subdomain enumeration using FFuF, we will use the -w and -u options.
-w: Specifies the subdomains word list.
-u: Specifies the target.
The command:
ffuf -w Discovery/DNS/subdomains-top1million-5000.txt -u http://FUZZ.target.com
If we want to expedite the process, we can increase the value for the -t option.
Fuzzing using FFUF (Discover Hidden Endpoints)
To perform fuzzing using FFuF, we will use the -w and -u options.
-w: Specifies the subdomains word list.
-u: Specifies the target.
The command:
ffuf -w Discovery/Web-Content/raft-large-directories-lowercase.txt:FUZZ -u http://vulnweb.com/FUZZ
Note: You can select the word list as you want.
Recursive Fuzzing
In FFuF, we can enable recursive scanning with the -recursion flag, and we can specify the depth with the -recursion-depth flag. If we specify -recursion-depth 1, it will only fuzz the main directories and their direct sub-directories.
ffuf -w /opt/useful/SecLists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://target.com/FUZZ -recursion -recursion-depth 1
Extension Fuzzing using FFUF
When we cannot manually locate any links or pages, we will once again utilize web fuzzing to see if the directory contains any hidden pages. However, before we start, we must find out what types of pages the website uses, like .html, .aspx, .php, or something else.
One common way to identify that is by finding the server type through the HTTP response headers and guessing the extension. For example, if the server is Apache, then it may be .php, or if it was IIS, then it could be .asp or .aspx, and so on. This method is not very practical, though. So, we will again utilize FFuF to fuzz the extension.
To perform fuzzing using FFuF, we will use the -w and -u options.
-w: Specifies the subdomains word list.
-u: Specifies the target.
The command:
ffuf -w /opt/useful/SecLists/Discovery/Web-Content/web-extensions.txt:FUZZ -u http://target.com/blog/indexFUZZ
Discover V-Host using FFUF
First, we need to know what the V-Host is:
The key difference between VHosts and subdomains is that a VHost is basically a 'sub-domain' served on the same server and has the same IP, such that a single IP could be serving two or more different websites.
To perform V-Host discovery using FFuF, we will use the -w, -u, and -H options.
-w: Specifies the subdomains word list.
-u: Specifies the target.
-H: Adds HOST Header.
The command:
ffuf -w /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://target.com/ -H 'Host: FUZZ.target.com'
Discover Get Params using FFUF
ffuf -w /opt/useful/SecLists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://target.com/admin/admin.php?FUZZ=key -fs unique-fs-value
Discover POST Params using FFUF
ffuf -w /opt/useful/SecLists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://target.com/admin/admin.php -X POST -d 'FUZZ=key' -H 'Content-Type: application/x-www-form-urlencoded' -fs unique-fs-value
Value Fuzzing
This section will discuss fuzzing for parameter values, which should be fairly similar to fuzzing for parameters. Value fuzzing may be useful for IDOR bugs.
ffuf -w ids.txt:FUZZ -u http://target.com/admin/admin.php -X POST -d 'id=FUZZ' -H 'Content-Type: application/x-www-form-urlencoded' -fs unique-fs-value

No comments yet