Skip to content

Web Tool - WFuzz

web offensive

Web Tool - WFuzz web saldırı yüzeyidir. Giriş noktalarını izole edip kanıtlanabilir etki (okuma, yazma, RCE, auth bypass) üretmeye odaklan.

  1. Web Tool - WFuzz giriş noktalarını (param/header/cookie/upload/API) haritala.

  2. Hedefe özgü payload ve araçlarla hipotezi doğrula.

  3. Okuma/yazma/RCE/bypass etkisini somut kanıtla.

  4. Zincirleme senaryo ve kanıt paketini tamamla.

Hedef yığını, endpoint’leri ve auth sınırını netleştir.

Terminal window
curl -skI https://TARGET/
Terminal window
whatweb -a 3 https://TARGET
Terminal window
katana -u https://TARGET -jc -d 3 -o crawl.txt
Terminal window
ffuf -u https://TARGET/FUZZ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -mc 200,204,301,302,403
Terminal window
arjun -u https://TARGET/api/v1/item --get
Terminal window
wfuzz -c -z file,/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt --hc 404 https://TARGET/FUZZ
Terminal window
wfuzz -c -z file,users.txt -z file,pass.txt -d 'user=FUZZ&pass=FUZ2Z' --hc 401 https://TARGET/login
Terminal window
wfuzz -c -z range,1-1000 --hl 12 https://TARGET/api/user/FUZZ
Terminal window
wfuzz -c -z file,params.txt -X POST -d 'FUZZ=test' https://TARGET/

Web Tool - WFuzz sonuçları hedef sürüme ve yığına göre değişir. Her başarılı adımı request/response ile kaydet; sonraki pivot’u not et.

Terminal window
curl -sk https://TARGET/robots.txt
Terminal window
nuclei -u https://TARGET -as -silent
Terminal window
ffuf -u https://TARGET/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc 200,204,301,302,403
GET / HTTP/1.1
Host: TARGET
Accept: */*
Terminal window
mkdir -p evidence/web && tee evidence/web/notes.txt

Bu ekler keşif ve kanıt paketini hızlandırır; asıl sömürü üstteki bölümlerdeki konu-özel payload’larla yapılır.

Terminal window
curl -sk https://TARGET/robots.txt
Terminal window
curl -sk https://TARGET/sitemap.xml
Terminal window
ffuf -u https://TARGET/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc 200,204,301,302,403
Terminal window
nuclei -u https://TARGET -as -silent
GET / HTTP/1.1
Host: TARGET
Accept: */*
Terminal window
mkdir -p evidence/web && tee evidence/web/notes.txt
request/response
zaman damgası
kullanılan hesap
etki özeti
Terminal window
curl -sk https://TARGET/ -D evidence/web/headers.txt -o evidence/web/body.html