Files
AJ ONeal 13ea83f963 ref: remove all releases.js files and _common/ fetchers
These files are no longer loaded at runtime. All release data now comes
from _cache/YYYY-MM/{pkg}.json files generated by the Go webicached daemon.

Deleted:
- 94 {pkg}/releases.js files (per-package upstream fetchers)
- 8 _common/*.js files (github.js, gitea.js, git-tag.js, fetcher.js, etc.)

Updated:
- _webi/classify-one.js: reads from cache instead of require(releases.js)
- Fixed hardcoded triplet key to use dynamic lookup
2026-03-11 16:24:28 -06:00
..
2026-03-08 19:38:49 -06:00

title, homepage, tagline
title homepage tagline
ffuf https://github.com/ffuf/ffuf Fuzz Faster U Fool: A fast web fuzzer written in Go.

To update or switch versions, run webi ffuf@stable (or @v2, @beta, etc).

Files

These are the files / directories that are created and/or modified with this install:

~/.config/envman/PATH.env
~/.local/bin/ffuf

Cheat Sheet

ffuf is a powerful web fuzzer written in Go. With a range of functionalities and fast performance, it's a must-have tool for penetration testers and security researchers.

ffuf mascot

Rotate through wordlists to discover and report exposed URLs, domains, etc.

# fuff -w <list>[:VAR] -u 'https://<target>/<VAR>'
fuff -w ./fuzz-Bo0oM.txt -u 'https://ffuf.io.fi/FUZZ
fuff \
    -w ./fuzz-Bo0oM.txt:'FUZZ_PATH' \
    -w ./subdomains-top1million-5000.txt:'FUZZ_SUB' \
    -u  'https://FUZZ_SUB.ffuf.io.fi/FUZZ_PATH'

How to get ffuf wordlists

Download Source Desc
onelistforallmicro.txt OneListForAll Words, Paths, Files
fuzz-Bo0oM.txt SecLists/Fuzzing Words, Paths, Files
subdomains-top1million-5000.txt SecLists/.../DNS Common Subdomains
burp-parameter-names.txt SecLists/.../Web-Content HTTP Query Params
urls-wordpress-3.3.1.txt SecLists/.../URLs WordPress v3 Paths

These were pulled from the resources mentioned in ffuf wiki: Wordlistt Resources:

How to Discover Exposed Content

For typical directory discovery:

ffuf -w ./onelistforallmicro.txt:'FUZZ' -u https://example.com/FUZZ

How to check for Domain Fronting (VHost Discovery)

Assuming a default virtualhost response size:

ffuf \
    -w ./subdomains-top1million-5000.txt:'SUB' \
    -u https://example.com \
    -H "Host: SUB.example.com" \
    -fs 4242

How to Fuzz GET Parameters

For fuzzing GET parameter names:

ffuf \
    -w ./burp-parameter-names.txt:'KEY' \
    -u https://example.com/script.php?KEY=test_value \
    -fs 4242

More Resources

See ffuf wiki: https://github.com/ffuf/ffuf/wiki.