Skip to content

FFUF

Fast web fuzzer that discovers directories, files, virtual hosts, and parameters on web servers.

Self-hostedNot yet verified
Report issue
MIT★ 14000Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse security tools →

What's next with FFUF?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is FFUF?

FFUF is an open-source web fuzzer written in Go, designed for rapid discovery of hidden endpoints, directories, and parameters on web servers. Its primary purpose is to assist security professionals in identifying vulnerabilities through systematic fuzzing of web applications. The tool is widely used by penetration testers, ethical hackers, and security researchers to uncover potential security weaknesses such as misconfigured files, exposed APIs, or unauthenticated endpoints. FFUF addresses the challenge of manually scanning large web surfaces by automating the process of sending crafted requests to identify responsive or sensitive resources. Its speed and efficiency make it a critical component in security testing workflows, particularly for reconnaissance phases of penetration testing.

How it works

FFUF (Fuzz Faster U Fool) is a fast, Go-based tool for web application security testing. It enables users to discover hidden files, directories, and parameters by systematically sending fuzzed requests to target URLs. The tool is designed to streamline the process of identifying vulnerabilities such as exposed endpoints, misconfigured servers, or unsecured APIs, which are often critical in penetration testing and security audits. FFUF supports directory discovery, virtual host discovery without DNS records, GET/POST parameter fuzzing, and POST data fuzzing. For example, it can recursively scan for hidden directories like /admin or /backup by varying path parameters. It also identifies virtual hosts by testing subdomains without requiring DNS resolution.

How to use it

  1. 1Install FFUF via package managers like apt (sudo apt install ffuf) or download binaries from its GitHub repository. 2. Run basic directory discovery with `ffuf -u http://target.com/FUZZ` to fuzz paths. 3. Use `-t` to specify thread count and `-mc` to filter response codes (e.g., `-mc 200,403`). 4. Combine with `-w` for custom wordlists to target specific parameters or endpoints. Practical tips include using configuration files for repeated tasks, leveraging external mutators for specialized fuzzing, and filtering results with `-o` to save output for later analysis.

What it can do

  • web fuzzer

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/ffuf/ffuf
  • license: MIT — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
  • Virtual host discovery requires the target server to respond to subdomain requests, which may not always be feasible.
  • False positives may occur when fuzzing large URL spaces, requiring manual verification.
  • Depends on valid target URLs; ineffective against rate-limited or blocked endpoints.
  • Lacks a graphical interface, relying on command-line interaction for configuration and output.

Understanding the result

Fast web fuzzer that discovers directories, files, virtual hosts, and parameters on web servers.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(ffuf/ffuf)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with ffuf/ffuf. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

How does FFUF differ from traditional directory brute-forcing tools?

FFUF uses a more efficient fuzzing engine with concurrent request handling, allowing it to scan large URL spaces faster than tools like DirBuster. It also supports advanced features like virtual host discovery and parameter fuzzing, which are not typically available in older tools.

How does FFUF handle HTTP request headers and cookies?

FFUF allows customization of headers using the `-H` flag and cookie data with `-b`. These parameters can be used to simulate authenticated sessions or set custom headers for testing, making it adaptable to scenarios requiring specific request contexts.

How do I fuzz POST parameters with a custom payload file?

Use the `-w` flag to specify a wordlist file for POST data, e.g., `ffuf -u http://target.com/login -X POST -d 'username=FUZZ' -w payloads.txt`. Replace `payloads.txt` with your custom payload list to test different values for the `username` field.

How does FFUF compare to tools like sqlmap or dirbuster?

FFUF is a general-purpose fuzzer focused on discovery, while sqlmap specializes in SQL injection testing. DirBuster is a traditional directory brute-forcer with fewer advanced features. FFUF outperforms these tools in speed and flexibility but lacks the specialized exploitation capabilities of sqlmap.

What should I do if FFUF times out during a scan?

Timeouts often occur due to rate limiting or slow server responses. Adjust the `-t` flag to reduce concurrency, use the `-mc` flag to filter for specific response codes, or pause the scan to avoid triggering defensive mechanisms. Ensure the target server allows the scan rate.

Spotted something wrong with FFUF, or want to maintain it? See how to help.