Web Fuzzing
常用指令
1
3
4
1.ffuf 備用
ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -u http://IP:PORT/FUZZbffuf -w /usr/share/seclists/Discovery/Web-Content/common.txt -u http://IP:PORT/FUZZ -e .php,.html,.txt,.bak,.js -vffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -u http://IP:PORT/FUZZ -e .html -recursion -recursion-depth 2 -rate 500PikachuN@htb[/htb]$ git clone https://github.com/PandaSt0rm/webfuzz_api.git PikachuN@htb[/htb]$ cd webfuzz_api PikachuN@htb[/htb]$ pip3 install -r requirements.txt PikachuN@htb[/htb]$ python3 api_fuzzer.py http://IP:PORT
2. 參數模糊測試(Parameter Fuzzing)
GET 參數測試
POST 參數測試
3. 進階控制選項
參數
功能
最后更新于
这有帮助吗?