How to use ffuf - Hacker Toolbox

Поделиться
HTML-код
  • Опубликовано: 11 сен 2024
  • ffuf is quickly becoming a key tool for bug bounty hunters, but how do you use it? In this video I start at the basics showing some really neat features of ffuf and how you can use some simple one-liners to do rather complex fuzzing!
    Did you know this episode was sponsored by Intigriti? Sign up with my link go.intigriti.co... I'm so pleased with everyone's positive response to the Intigriti sponsorship and I'm so pleased you folks are finding bugs and even finding your first bugs! Thank you for being awesome!
    ffuf is well known as a brute-forcing tool, but did you know it can be used for so much more than directory discovery?? I didn't! The FUZZ keyword is so powerful you can use it to fuzz headers, parameters, and add filters to cut down false positives. With the right wordlist ffuf can become the go-to tool for bug hunting.
    Resources
    - ffuf : github.com/ffu...
    - Installing ffuf into the PATH OSX : superuser.com/...
    - Installing ffuf into the PATH Windows : superuser.com/...
    - SecLists : github.com/dan...
    - TomNomNom's talk : • Who, What, Where, When...
    - Here are the one-liners I use: gist.github.co...
    - My ffuf translator: insiderphd.dev...
    - 0xatul's jq translator: jqplay.org/s/x...
    - Patrik's jq translator: / 1301086393108758528
    Connect with me
    - Twitter : / insiderphd
    - InsiderPhD Discord : / discord
    - Patreon : / insiderphd

Комментарии • 122

  • @dhruvkandpal9909
    @dhruvkandpal9909 4 года назад +23

    Oh my god!!! THIS VIDEO DESERVES A HUGE ROUND OF APPLAUSE from the BUG BOUNTY community!! I ABSOLUTELY LOVED IT Katie!!

    • @richardjones9598
      @richardjones9598 3 года назад +1

      Is very clear and concise info tbf, great job, Katie!

  • @jawadsaqib1260
    @jawadsaqib1260 4 года назад +7

    You are just awesome explaining everything with so much detail and in-depth knowledge. Thank you for making stuff. More power to you

  • @hashimmajid7905
    @hashimmajid7905 Год назад

    thank you for your content, it's logical to read docs for any tools, but watching a pro like you using a tool and getting inside your mindset and feeling your enthusiasm is much better learning process, this channel is a gold mine!

  • @InfoSecIntel
    @InfoSecIntel 4 года назад +1

    That replay proxy option blew my mind. Thank you!

  • @Abhijitkamath14
    @Abhijitkamath14 2 года назад

    I really like the way you explain things .... the accent, the tone and all ... smooth

  • @Ragab0t
    @Ragab0t 3 года назад

    Awesome video thanks for sharing! BTW One of the coolest things about teaching about a new subject is how much new stuff you end up learning about said subject. That's probably why teaching is the best way to learn!

  • @carp6509
    @carp6509 3 года назад

    I don't know how anyone could downvote this. Amazing content! Thank you so much!

  • @wnmetal666
    @wnmetal666 2 года назад

    Amazing explanation and examples of the features. I was struggling with too many code 200, this video helped me get that filtered out properly.

  • @arman-ez3ir
    @arman-ez3ir 3 месяца назад

    love these kind of tuts, well done

  • @sumanparajuli229
    @sumanparajuli229 4 года назад +6

    Mam..Please...... can you create a video on how to implement business logic in bug hunting and money practically on a real websites or web apps???????????

    • @InsiderPhD
      @InsiderPhD  4 года назад +9

      I really want to do some live hacking on a real target! But I'm still trying to speak to other hackers/program managers to figure out what the best way might be to demo without breaking confidentiality!

    • @sumanparajuli229
      @sumanparajuli229 4 года назад

      @@InsiderPhD Ok mam... so please i highly request you to make more videos on business logic for bug...

  • @kon5791
    @kon5791 2 года назад

    thanks for keeping it short and sweet! :) I love me a conciese and easy to follow explanation

  • @RUFAID
    @RUFAID 4 года назад +3

    Thanks for making this type of video. And it is begginer friendly .
    Plz one favor
    Plz incress the voice sound little more . Don't take tress, but increase it plz plz please

    • @InsiderPhD
      @InsiderPhD  4 года назад

      I've addressed this problem in the video pipeline and it should be fixed now for future videos

  • @fenilshah9221
    @fenilshah9221 4 года назад

    Claps! This is what I was waiting for! I hope you'll soon cover other tools such as gau,gf,etc!

    • @InsiderPhD
      @InsiderPhD  4 года назад +3

      I'm thinking the next videos will be recon: subdomain enum and then a standalone video on amass! But I'll note these down !

  • @jasonmikinskiwallet4308
    @jasonmikinskiwallet4308 4 года назад +1

    Oh WOW!!!!!! This is amazingggg. Ffuf dream tool.

  • @theblackzeini9004
    @theblackzeini9004 Год назад

    The way you explain is amazing, keep goin'

  • @rosa3709
    @rosa3709 Год назад

    The content is great and easy to understand! Thanks 🙏🏼

  • @kabirsuda
    @kabirsuda 4 года назад +2

    Thanks for the video, love it!💛

  • @varunmehta3230
    @varunmehta3230 3 года назад

    Such a awesome knowledge sharing video. Thanks a lot ❤️. love from India .

  • @DeLFeTube
    @DeLFeTube 2 года назад

    What an insanely good video! Thank you!

  • @ardaucd
    @ardaucd Год назад

    Is the playlist Everything API Hacking up to date, are all API videos in this channel in this list?

  • @joakimtauren1286
    @joakimtauren1286 4 года назад +1

    Super great content! Thank you so much!

  • @TheEasternCoder
    @TheEasternCoder 3 года назад

    Concept of using ffuf replay proxy is amazing. Thanks for introducing a great tool .
    Is there any method to pipeline the output of crunch/any wordlist generator to ffuf ??🙄

  • @mi2has
    @mi2has 4 года назад +1

    Thank you for the great video !

  • @d-rey1758
    @d-rey1758 Год назад

    Cool vid! any info on the steps between ffuf finds the errors and claiming a bounty?

  • @akshaydeodare6149
    @akshaydeodare6149 4 года назад

    the video is very dark ! It takes effort to look whats written on the screen ! content : Awesome as always

    • @InsiderPhD
      @InsiderPhD  4 года назад +2

      Thank you for the feedback!

    • @akshaydeodare6149
      @akshaydeodare6149 4 года назад

      InsiderPhD for example : the json part from 10:27

    • @InsiderPhD
      @InsiderPhD  4 года назад

      It can sometimes be an issue since people might be watching my videos at a lower quality or on mobile and I'm a bit of an idiot and forget that sometimes! So esp as I try out the dark mode theme, it's useful to get this kind of feedback!

  • @super3d201
    @super3d201 Год назад

    Really great Video and detailed aswell. Thanks, that helped me alot

  • @maakthon5551
    @maakthon5551 Год назад

    Great as usual , Thanks.

  • @ygorsardinha5521
    @ygorsardinha5521 Год назад

    Katie you Rock!

  • @hellb0y794
    @hellb0y794 2 года назад

    Great video katie, thanks 🚀

  • @Thenileshpatil
    @Thenileshpatil Год назад

    hey katie help with what should we look on which type of target

  • @d3vashishs0ni
    @d3vashishs0ni 4 года назад

    A very informative video. thank you very much 😊😊

  • @unknownerror58
    @unknownerror58 2 года назад +1

    It's not installing in Termux😥😥

  • @7he7hief95
    @7he7hief95 4 года назад +1

    Thanks Kate, you make things clearer as always and I love your enthusiasm. Kisses from 7he7hief * meow

  • @PhayulDigest
    @PhayulDigest 3 года назад

    Awesome video, thanks so much!

  • @_0x01m
    @_0x01m 3 года назад

    thank you it was super cool video i learn more with u ..

  • @AkashwithUS
    @AkashwithUS 4 года назад

    I waited for this ♥️

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      I hope it was worth the wait!

    • @AkashwithUS
      @AkashwithUS 4 года назад

      @@InsiderPhD yes 🙂
      I know about some bugs like spf, cors, xss, clickjacking, subdomain takeover.
      How to know this website has those vulnerabilities ..... Automatically...
      Then please recommend me to where to learn vulnerabilities ....
      I hope you reply

  • @brokeitguyio
    @brokeitguyio 4 года назад +1

    Thanks for the tutorial

  • @jozefwoo8079
    @jozefwoo8079 Год назад

    Very good video. If I may nitpick: it's intigrity and not integrity 🙂

  • @orlyounotinbaires
    @orlyounotinbaires 4 года назад

    Excellent video as always, love your enthusiasm!
    PS: you should do a video together with Stök :D

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      One day I hope so! We haven't found a good time for us both yet :) though we have had a chat and got a concept of what we wanna do!

  • @picious
    @picious 4 года назад +1

    when Brute force is out of scope it means that you can't run FFUF or no?? , Thank you for the video !

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      You can use ffuf! Brute force being out of scope usually means brute forcing user/password combos, they might ask for w delay though and a limit to x requests a second, so keep an eye out for that

    • @picious
      @picious 4 года назад

      @@InsiderPhD thank you for your reply :)

  • @kandarpmishra6009
    @kandarpmishra6009 3 года назад

    How do i know its an API request or response ??

  • @nowonder9466
    @nowonder9466 4 года назад

    At 18.02 you said that ME will come from the action wordlist and FUZZ will come from that wordlist while pointing at the second FUZZ. What did you mean by that? The FUZZ part.

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      Basically if you do -w wordlist.txt:WORD you can use multiple wordlists, or fuzz in multiple areas, or do both!

  • @shayboual1892
    @shayboual1892 3 года назад

    very useful and informative video

  • @haileleulgirma1087
    @haileleulgirma1087 5 месяцев назад

    I wanted to be excited just like you, but I just can't find the reason to use it over burp intruder. Given the world lists, both can do the job

    • @InsiderPhD
      @InsiderPhD  5 месяцев назад +1

      I also like intruder but I know a lot of people want speed w/o having to pay for pro, so ffuf is a good option

  • @anshusharma5199
    @anshusharma5199 4 года назад

    Someone told me today to use it and see how lucky I am,
    Thanks 🙏😊

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      You're welcome 😊 I'm reading your mind obviously :P

    • @anshusharma5199
      @anshusharma5199 4 года назад

      @@InsiderPhD thanks again I like the way you teach
      (10¹²³ * 👍)

  • @omerfarooqdemir9907
    @omerfarooqdemir9907 3 года назад

    thanks for this video. THIS VIDEO AMAZING

  • @mastawitcha231
    @mastawitcha231 4 года назад +1

    Does it do the same job as wfuzz in every aspect or is one better than the other? both are fuzzing tools

    • @InsiderPhD
      @InsiderPhD  4 года назад +2

      Does the same job, it's written in go so it's a little faster, but it's personal preference. The cool thing about ffuf is the focus on bug bounties and how active the developer is in the community! But feature wise very very similar

  • @vanshajdhar9223
    @vanshajdhar9223 3 года назад

    Amazing video 👌👌👌

  • @cyberindia1
    @cyberindia1 4 года назад

    Nice explanation

  • @remonsec
    @remonsec 4 года назад

    Thanks a lot.

  • @saminbinhumayun858
    @saminbinhumayun858 6 месяцев назад

    If there is scope given in bb program do we need to do directory bruteforcing?

  • @ashhadhats4842
    @ashhadhats4842 4 года назад

    Will u creste a video how to creste a custom word list i watching tomnomnom but please u can create your own

    • @InsiderPhD
      @InsiderPhD  4 года назад

      This is actually coming soon :) it's something I'm working on a methodology for! But it'll be a while until it's ready!

  • @zeeshansaeed8997
    @zeeshansaeed8997 4 года назад

    Thanks, Katie for creating such awesome content.

  • @sy-gamer9556
    @sy-gamer9556 4 года назад

    Your videos are really awesome love it.also I want to ask something I have a jail broken ios device everything setup and ready to go and also I know a little bit of iOS knowledge but I can’t decide by myself what to choose iOS bug bounty or web any suggestion pls..

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      iOS has a big advantage and disadvantage: Almost no one is doing it, which means there's not as many resources BUT there's a lot more bugs to be found! I would focus on API hacking, it applies to both web+iOS and it's a good way to get started in iOS (EXACTLY the same bugs) without getting lost. I'm actually writing a video at the moment on how to hack on mobile APIs

    • @sy-gamer9556
      @sy-gamer9556 4 года назад

      InsiderPhD awesome thank u I was just confused a lot thank a lot Katie hugeeee love and thanks

    • @sy-gamer9556
      @sy-gamer9556 4 года назад

      And 1 more question what are the bugs to look for aside web bugs in iOS applications

  • @recon0x7f16
    @recon0x7f16 2 года назад

    how do u pipe with this

  • @mazingerzeta2xx788
    @mazingerzeta2xx788 4 года назад

    What is the difference between Ffuf and Amass? wich one id faster and less complicated to use?

    • @InsiderPhD
      @InsiderPhD  4 года назад

      Ffuf is easier for most things, amass has a lot of uses and can be quite complex to use

    • @mazingerzeta2xx788
      @mazingerzeta2xx788 4 года назад

      but they but they both perform same task right ?

  • @kevinnyawakira4600
    @kevinnyawakira4600 4 года назад

    thanks

  • @DavidRawls-b9p
    @DavidRawls-b9p 8 дней назад

    Grady Inlet

  • @josephnimsara3169
    @josephnimsara3169 4 года назад

    awesome

  • @skyawesome7362
    @skyawesome7362 4 года назад

    The command doesn’t work on mac

    • @InsiderPhD
      @InsiderPhD  4 года назад

      You need to install ffuf first using the GitHub link :)

  • @roninhacked2045
    @roninhacked2045 4 года назад

    Hey katie , I am new to hacking
    WHAT is the best OS that you recommend to me
    Please reply soon

    • @InsiderPhD
      @InsiderPhD  4 года назад

      Whatever you're using right now is fine! You don't need to use any OS to get into hacking!

    • @roninhacked2045
      @roninhacked2045 4 года назад

      Even if it is windows
      But how to install them

  • @moathaljmaan7331
    @moathaljmaan7331 2 года назад

    🖐have fife for your explain

  • @ashleypursell9702
    @ashleypursell9702 4 года назад +1

    this is actually as close as command line burp intruder as you can get

    • @InsiderPhD
      @InsiderPhD  4 года назад +4

      *cough* if you don't have premium it's better than command line burp intruder, it's not speed limited
      Wow what a weird cough, covid amiright?

  • @GregoryTripp-p7r
    @GregoryTripp-p7r 8 дней назад

    Matilda Extension

  • @josephnimsara3169
    @josephnimsara3169 4 года назад

    can you add nest bug bounty series

    • @InsiderPhD
      @InsiderPhD  4 года назад

      Nest?

    • @josephnimsara3169
      @josephnimsara3169 4 года назад

      @@InsiderPhD sorry next bug bounty series

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      @@josephnimsara3169 Aha! I'm actually working on a video right now, spoiler alert on account takeovers, it's just not quittteeee ready to be released yet!

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      It's almost done though, 90%-ish

  • @ricardotech
    @ricardotech 4 года назад +2

  • @MH-tw1qi
    @MH-tw1qi 4 года назад

    Hmm i will use ffuf instead dirsearch

  • @saikiranlingadally1036
    @saikiranlingadally1036 4 года назад

    ❤️

  • @PullmanMagee-t6u
    @PullmanMagee-t6u 3 дня назад

    Moore Elizabeth Lopez Jeffrey Martinez Christopher

  • @AkashwithUS
    @AkashwithUS 4 года назад

    Hi mam I know only terminal and cmd what is this looks new..???

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      Check out my video on API enumeration to get a better idea of why you might use a tool like ffuf

    • @AkashwithUS
      @AkashwithUS 4 года назад

      @@InsiderPhD thanks for your reply 🙂 please make a live session on ffuf🔥

    • @InsiderPhD
      @InsiderPhD  4 года назад +1

      I have insider knowledge that the video you seek is on it's way but by another creator ;)

  • @sechunter1903
    @sechunter1903 4 года назад

    😍 😛

  • @user-dn1oh3jf3g
    @user-dn1oh3jf3g 2 года назад

    hgyug

  • @abelimathiasi7509
    @abelimathiasi7509 3 года назад

    25+ mins and i ddnt even get to know what you where teaching ... i cnt even see the help menu of the TOOL SHAME ON YOU .....

    • @Sakuraigi
      @Sakuraigi 2 месяца назад

      She is great. You suck

  • @logmantarig
    @logmantarig 3 года назад

    This actually an Awesome video and great tool with an invaluable information thanks a lot, probably dislikers are Gobuster users.