File Nº 0x6D / Subject: m0rgxn
Local --:--:--
← All notesExhibit B · Filed 26 Jan 2026 · 2 min read

FFUF Fuzzing Techniques

Filed

Exhibit B — cover
we should also consider matching or filtering the sizes and statuses of responses, as ffuf sometimes returns a lot unwanted directories that would just cover up the important ones, we do this to make the output more readable that’s all. Under the recursion depth option we need to put how deep the search is wanted to be. For example,if we specify -recursion-depth 1, it will only fuzz the main directories and their direct sub-directories. If any sub-sub-directories are identified (like /login/user, it will not fuzz them for pages) The -e option stands for extension that will be automatically appended whenever a directory/subdirectory is discovered. The -v option gives us the full url to the fuzzed pages. If this doesn’t return results it doesn’t mean that there are no subdomains, it’s not necessarily true, but if there are subdomains, there aren’t public records of them. And that would take us to the V-host section. Vhosts vs. Sub-domains The key difference between VHosts and sub-domains is that a VHost is basically a 'sub-domain' served on the same server and has the same IP, such that a single IP could be serving two or more different websites. VHosts may or may not have public DNS records. VHost Fuzzing works with http headers specifically the Host header, because if we don’t do that we would have to add the entire wordlist to our host in the /etc/hosts file, that would be unpractical. You can review this in the file inclusion module notes, i will just add the command here. this is a case where ffuf would return a lot of 200 statuses, we need to filter out the unwanted response size Unlike the GET request, POST request can be sent from the browser with a simple url and query ?. Post requests are passed in the data section within the http request. To fuzz the data with ffuf this is the command that we use We include the Content-Type header because that’s how PHP expects POST requests to be. This is the last step before exploitation, after we find subdirectories/directories, pages and parameters, all we need to do now is brute force the value of the parameter. We can do that by creating a custom wordlist that has numbers for example ranging from 0 to 100000 or any other form of wordlist we want. And then we go ahead and FUZZ the value of the already fuzzed parameter. NOTE: Keep the same method used for fuzzing the parameter in the first place.
§ — Also in evidenceView all →

Other exhibits


Exhibit L · 04 Sept 2026

SQL Injection

PortSwigger Web Security Academy notes on detecting and exploiting SQL injection, from UNION attacks to blind and out-of-band techniques

Filed
Exhibit K · 18 Aug 2026 · Azure Security

Modeling Managed-Identity Privilege Escalation as an Attack Graph

A framework for treating Azure managed-identity abuse in hybrid Entra ID environments as a graph-reachability problem. I define the node and edge types, ground each edge in Azure RBAC semantics, show how my tool Fenrir uses the model to answer one question conservatively, and work through a case study in my own lab. Framework and systematization, not an empirical study.

Filed
§ Contents