Что это
Wfuzz — это инструмент, предназначенный для перебора веб-приложений. Его можно использовать для поиска ресурсов, не связанных с каталогами, сервлетами, скриптами и т. д., параметров GET и POST для перебора различных типов инъекций (SQL, XSS, LDAP и т. д.), перебора параметров форм (пользователь/пароль), фаззинга и т. д.
Оригинал описания (EN)
Wfuzz is a tool designed for bruteforcing Web Applications, it can be used for finding resources not linked directories, servlets, scripts, etc, bruteforce GET and POST parameters for checking different kind of injections (SQL, XSS, LDAP,etc), bruteforce Forms parameters (User/Password), Fuzzing, etc.
Пример использования
root@kali:~# wfuzz --help
default
default
********************************************************
* Wfuzz 3.1.0 - The Web Fuzzer *
* *
* Version up to 1.4c coded by: *
* Christian Martorella ([email protected]) *
* Carlos del ojo ([email protected]) *
* *
* Version 1.4d to 3.1.0 coded by: *
* Xavier Mendez ([email protected]) *
********************************************************
Usage: wfuzz [options] -z payload,params <url>
FUZZ, ..., FUZnZ wherever you put these keywords wfuzz will replace them with the values of the specified payload.
FUZZ{baseline_value} FUZZ will be replaced by baseline_value. It will be the first request performed and could be used as a base for filtering.
Options:
-h/--help : This help
--help : Advanced help
--filter-help : Filter language specification
--version : Wfuzz version details
-e <type> : List of available encoders/payloads/iterators/printers/scripts
--recipe <filename> : Reads options from a recipe. Repeat for various recipes.
--dump-recipe <filename> : Prints current options as a recipe
--oF <filename> : Saves fuzz results to a file. These can be consumed later using the wfuzz payload.
-c : Output with colors
-v : Verbose information.
-f filename,printer : Store results in the output file using the specified printer (raw printer if omitted).
-o printer : Show results using the specified printer.
--interact : (beta) </code></pre>
Пакеты и установка
wfuzz
Брутфорсер веб-приложений
Установка: sudo apt install wfuzz
Официальная документация
Комментарии