How to use ffuf - Hacker Toolbox

Поділитися
Вставка
  • Опубліковано 1 вер 2020
  • ffuf is quickly becoming a key tool for bug bounty hunters, but how do you use it? In this video I start at the basics showing some really neat features of ffuf and how you can use some simple one-liners to do rather complex fuzzing!
    Did you know this episode was sponsored by Intigriti? Sign up with my link go.intigriti.com/katie I'm so pleased with everyone's positive response to the Intigriti sponsorship and I'm so pleased you folks are finding bugs and even finding your first bugs! Thank you for being awesome!
    ffuf is well known as a brute-forcing tool, but did you know it can be used for so much more than directory discovery?? I didn't! The FUZZ keyword is so powerful you can use it to fuzz headers, parameters, and add filters to cut down false positives. With the right wordlist ffuf can become the go-to tool for bug hunting.
    Resources
    - ffuf : github.com/ffuf/ffuf
    - Installing ffuf into the PATH OSX : superuser.com/questions/7150/...
    - Installing ffuf into the PATH Windows : superuser.com/questions/15560...
    - SecLists : github.com/danielmiessler/Sec...
    - TomNomNom's talk : • Who, What, Where, When...
    - Here are the one-liners I use: gist.github.com/InsiderPhD/5c...
    - My ffuf translator: insiderphd.dev/tools/ffuf.html
    - 0xatul's jq translator: jqplay.org/s/x8xFbIk6S8
    - Patrik's jq translator: / 1301086393108758528
    Connect with me
    - Twitter : / insiderphd
    - InsiderPhD Discord : / discord
    - Patreon : / insiderphd
  • Розваги

КОМЕНТАРІ • 117

  • @dhruvkandpal9909
    @dhruvkandpal9909 3 роки тому +23

    Oh my god!!! THIS VIDEO DESERVES A HUGE ROUND OF APPLAUSE from the BUG BOUNTY community!! I ABSOLUTELY LOVED IT Katie!!

    • @richardjones9598
      @richardjones9598 3 роки тому +1

      Is very clear and concise info tbf, great job, Katie!

  • @hashimmajid7905
    @hashimmajid7905 Рік тому

    thank you for your content, it's logical to read docs for any tools, but watching a pro like you using a tool and getting inside your mindset and feeling your enthusiasm is much better learning process, this channel is a gold mine!

  • @jawadsaqib1260
    @jawadsaqib1260 3 роки тому +6

    You are just awesome explaining everything with so much detail and in-depth knowledge. Thank you for making stuff. More power to you

  • @Ragab0t
    @Ragab0t 3 роки тому

    Awesome video thanks for sharing! BTW One of the coolest things about teaching about a new subject is how much new stuff you end up learning about said subject. That's probably why teaching is the best way to learn!

  • @wnmetal666
    @wnmetal666 Рік тому

    Amazing explanation and examples of the features. I was struggling with too many code 200, this video helped me get that filtered out properly.

  • @carp6509
    @carp6509 2 роки тому

    I don't know how anyone could downvote this. Amazing content! Thank you so much!

  • @Abhijitkamath14
    @Abhijitkamath14 Рік тому

    I really like the way you explain things .... the accent, the tone and all ... smooth

  • @kon5791
    @kon5791 Рік тому

    thanks for keeping it short and sweet! :) I love me a conciese and easy to follow explanation

  • @InfoSecIntel
    @InfoSecIntel 3 роки тому

    That replay proxy option blew my mind. Thank you!

  • @arman-ez3ir
    @arman-ez3ir 25 днів тому

    love these kind of tuts, well done

  • @theblackzeini9004
    @theblackzeini9004 Рік тому

    The way you explain is amazing, keep goin'

  • @rosa3709
    @rosa3709 9 місяців тому

    The content is great and easy to understand! Thanks 🙏🏼

  • @fenilshah9221
    @fenilshah9221 3 роки тому

    Claps! This is what I was waiting for! I hope you'll soon cover other tools such as gau,gf,etc!

    • @InsiderPhD
      @InsiderPhD  3 роки тому +2

      I'm thinking the next videos will be recon: subdomain enum and then a standalone video on amass! But I'll note these down !

  • @varunmehta3230
    @varunmehta3230 3 роки тому

    Such a awesome knowledge sharing video. Thanks a lot ❤️. love from India .

  • @DeLFeTube
    @DeLFeTube 2 роки тому

    What an insanely good video! Thank you!

  • @jasonmikinskiwallet4308
    @jasonmikinskiwallet4308 3 роки тому +1

    Oh WOW!!!!!! This is amazingggg. Ffuf dream tool.

  • @d3vashishs0ni
    @d3vashishs0ni 3 роки тому

    A very informative video. thank you very much 😊😊

  • @joakimtauren1286
    @joakimtauren1286 3 роки тому +1

    Super great content! Thank you so much!

  • @maakthon5551
    @maakthon5551 Рік тому

    Great as usual , Thanks.

  • @hellb0y794
    @hellb0y794 2 роки тому

    Great video katie, thanks 🚀

  • @mi2has
    @mi2has 3 роки тому +1

    Thank you for the great video !

  • @kabirsuda
    @kabirsuda 3 роки тому +2

    Thanks for the video, love it!💛

  • @super3d201
    @super3d201 Рік тому

    Really great Video and detailed aswell. Thanks, that helped me alot

  • @PhayulDigest
    @PhayulDigest 3 роки тому

    Awesome video, thanks so much!

  • @brokeitguyio
    @brokeitguyio 3 роки тому +1

    Thanks for the tutorial

  • @_0x01m
    @_0x01m 3 роки тому

    thank you it was super cool video i learn more with u ..

  • @ygorsardinha5521
    @ygorsardinha5521 Рік тому

    Katie you Rock!

  • @d-rey1758
    @d-rey1758 Рік тому

    Cool vid! any info on the steps between ffuf finds the errors and claiming a bounty?

  • @shayboual1892
    @shayboual1892 3 роки тому

    very useful and informative video

  • @TheEasternCoder
    @TheEasternCoder 3 роки тому

    Concept of using ffuf replay proxy is amazing. Thanks for introducing a great tool .
    Is there any method to pipeline the output of crunch/any wordlist generator to ffuf ??🙄

  • @omerfarooqdemir9907
    @omerfarooqdemir9907 3 роки тому

    thanks for this video. THIS VIDEO AMAZING

  • @cyberindia1
    @cyberindia1 3 роки тому

    Nice explanation

  • @sumanparajuli229
    @sumanparajuli229 3 роки тому +6

    Mam..Please...... can you create a video on how to implement business logic in bug hunting and money practically on a real websites or web apps???????????

    • @InsiderPhD
      @InsiderPhD  3 роки тому +9

      I really want to do some live hacking on a real target! But I'm still trying to speak to other hackers/program managers to figure out what the best way might be to demo without breaking confidentiality!

    • @sumanparajuli229
      @sumanparajuli229 3 роки тому

      @@InsiderPhD Ok mam... so please i highly request you to make more videos on business logic for bug...

  • @pianodotexe3852
    @pianodotexe3852 3 роки тому

    I waited for this ♥️

    • @InsiderPhD
      @InsiderPhD  3 роки тому +1

      I hope it was worth the wait!

    • @pianodotexe3852
      @pianodotexe3852 3 роки тому

      @@InsiderPhD yes 🙂
      I know about some bugs like spf, cors, xss, clickjacking, subdomain takeover.
      How to know this website has those vulnerabilities ..... Automatically...
      Then please recommend me to where to learn vulnerabilities ....
      I hope you reply

  • @vanshajdhar9223
    @vanshajdhar9223 3 роки тому

    Amazing video 👌👌👌

  • @Thenileshpatil
    @Thenileshpatil 9 місяців тому

    hey katie help with what should we look on which type of target

  • @orlyounotinbaires
    @orlyounotinbaires 3 роки тому

    Excellent video as always, love your enthusiasm!
    PS: you should do a video together with Stök :D

    • @InsiderPhD
      @InsiderPhD  3 роки тому +1

      One day I hope so! We haven't found a good time for us both yet :) though we have had a chat and got a concept of what we wanna do!

  • @remonsec
    @remonsec 3 роки тому

    Thanks a lot.

  • @zeeshansaeed8997
    @zeeshansaeed8997 3 роки тому

    Thanks, Katie for creating such awesome content.

  • @ardaucd
    @ardaucd 11 місяців тому

    Is the playlist Everything API Hacking up to date, are all API videos in this channel in this list?

  • @7he7hief95
    @7he7hief95 3 роки тому +1

    Thanks Kate, you make things clearer as always and I love your enthusiasm. Kisses from 7he7hief * meow

  • @RUFAID
    @RUFAID 3 роки тому +3

    Thanks for making this type of video. And it is begginer friendly .
    Plz one favor
    Plz incress the voice sound little more . Don't take tress, but increase it plz plz please

    • @InsiderPhD
      @InsiderPhD  3 роки тому

      I've addressed this problem in the video pipeline and it should be fixed now for future videos

  • @akshaydeodare6149
    @akshaydeodare6149 3 роки тому

    the video is very dark ! It takes effort to look whats written on the screen ! content : Awesome as always

    • @InsiderPhD
      @InsiderPhD  3 роки тому +2

      Thank you for the feedback!

    • @akshaydeodare6149
      @akshaydeodare6149 3 роки тому

      InsiderPhD for example : the json part from 10:27

    • @InsiderPhD
      @InsiderPhD  3 роки тому

      It can sometimes be an issue since people might be watching my videos at a lower quality or on mobile and I'm a bit of an idiot and forget that sometimes! So esp as I try out the dark mode theme, it's useful to get this kind of feedback!

  • @anshusharma5199
    @anshusharma5199 3 роки тому

    Someone told me today to use it and see how lucky I am,
    Thanks 🙏😊

    • @InsiderPhD
      @InsiderPhD  3 роки тому +1

      You're welcome 😊 I'm reading your mind obviously :P

    • @anshusharma5199
      @anshusharma5199 3 роки тому

      @@InsiderPhD thanks again I like the way you teach
      (10¹²³ * 👍)

  • @sy-gamer9556
    @sy-gamer9556 3 роки тому

    Your videos are really awesome love it.also I want to ask something I have a jail broken ios device everything setup and ready to go and also I know a little bit of iOS knowledge but I can’t decide by myself what to choose iOS bug bounty or web any suggestion pls..

    • @InsiderPhD
      @InsiderPhD  3 роки тому +1

      iOS has a big advantage and disadvantage: Almost no one is doing it, which means there's not as many resources BUT there's a lot more bugs to be found! I would focus on API hacking, it applies to both web+iOS and it's a good way to get started in iOS (EXACTLY the same bugs) without getting lost. I'm actually writing a video at the moment on how to hack on mobile APIs

    • @sy-gamer9556
      @sy-gamer9556 3 роки тому

      InsiderPhD awesome thank u I was just confused a lot thank a lot Katie hugeeee love and thanks

    • @sy-gamer9556
      @sy-gamer9556 3 роки тому

      And 1 more question what are the bugs to look for aside web bugs in iOS applications

  • @kevinnyawakira4600
    @kevinnyawakira4600 3 роки тому

    thanks

  • @kandarpmishra6009
    @kandarpmishra6009 2 роки тому

    How do i know its an API request or response ??

  • @mastawitcha231
    @mastawitcha231 3 роки тому +1

    Does it do the same job as wfuzz in every aspect or is one better than the other? both are fuzzing tools

    • @InsiderPhD
      @InsiderPhD  3 роки тому +2

      Does the same job, it's written in go so it's a little faster, but it's personal preference. The cool thing about ffuf is the focus on bug bounties and how active the developer is in the community! But feature wise very very similar

  • @nowonder9466
    @nowonder9466 3 роки тому

    At 18.02 you said that ME will come from the action wordlist and FUZZ will come from that wordlist while pointing at the second FUZZ. What did you mean by that? The FUZZ part.

    • @InsiderPhD
      @InsiderPhD  3 роки тому +1

      Basically if you do -w wordlist.txt:WORD you can use multiple wordlists, or fuzz in multiple areas, or do both!

  • @ashhadhats4842
    @ashhadhats4842 3 роки тому

    Will u creste a video how to creste a custom word list i watching tomnomnom but please u can create your own

    • @InsiderPhD
      @InsiderPhD  3 роки тому

      This is actually coming soon :) it's something I'm working on a methodology for! But it'll be a while until it's ready!

  • @josephnimsara3169
    @josephnimsara3169 3 роки тому

    awesome

  • @saminbinhumayun858
    @saminbinhumayun858 3 місяці тому

    If there is scope given in bb program do we need to do directory bruteforcing?

  • @jozefwoo8079
    @jozefwoo8079 Рік тому

    Very good video. If I may nitpick: it's intigrity and not integrity 🙂

  • @picious
    @picious 3 роки тому +1

    when Brute force is out of scope it means that you can't run FFUF or no?? , Thank you for the video !

    • @InsiderPhD
      @InsiderPhD  3 роки тому +1

      You can use ffuf! Brute force being out of scope usually means brute forcing user/password combos, they might ask for w delay though and a limit to x requests a second, so keep an eye out for that

    • @picious
      @picious 3 роки тому

      @@InsiderPhD thank you for your reply :)

  • @moathaljmaan7331
    @moathaljmaan7331 2 роки тому

    🖐have fife for your explain

  • @mazingerzeta2xx788
    @mazingerzeta2xx788 3 роки тому

    What is the difference between Ffuf and Amass? wich one id faster and less complicated to use?

    • @InsiderPhD
      @InsiderPhD  3 роки тому

      Ffuf is easier for most things, amass has a lot of uses and can be quite complex to use

    • @mazingerzeta2xx788
      @mazingerzeta2xx788 3 роки тому

      but they but they both perform same task right ?

  • @recon0x7f16
    @recon0x7f16 Рік тому

    how do u pipe with this

  • @roninhacked2045
    @roninhacked2045 3 роки тому

    Hey katie , I am new to hacking
    WHAT is the best OS that you recommend to me
    Please reply soon

    • @InsiderPhD
      @InsiderPhD  3 роки тому

      Whatever you're using right now is fine! You don't need to use any OS to get into hacking!

    • @roninhacked2045
      @roninhacked2045 3 роки тому

      Even if it is windows
      But how to install them

  • @haileleulgirma1087
    @haileleulgirma1087 2 місяці тому

    I wanted to be excited just like you, but I just can't find the reason to use it over burp intruder. Given the world lists, both can do the job

    • @InsiderPhD
      @InsiderPhD  2 місяці тому +1

      I also like intruder but I know a lot of people want speed w/o having to pay for pro, so ffuf is a good option

  • @unknownerror58
    @unknownerror58 Рік тому

    It's not installing in Termux😥😥

  • @josephnimsara3169
    @josephnimsara3169 3 роки тому

    can you add nest bug bounty series

    • @InsiderPhD
      @InsiderPhD  3 роки тому

      Nest?

    • @josephnimsara3169
      @josephnimsara3169 3 роки тому

      @@InsiderPhD sorry next bug bounty series

    • @InsiderPhD
      @InsiderPhD  3 роки тому +1

      @@josephnimsara3169 Aha! I'm actually working on a video right now, spoiler alert on account takeovers, it's just not quittteeee ready to be released yet!

    • @InsiderPhD
      @InsiderPhD  3 роки тому +1

      It's almost done though, 90%-ish

  • @ashleypursell9702
    @ashleypursell9702 3 роки тому +1

    this is actually as close as command line burp intruder as you can get

    • @InsiderPhD
      @InsiderPhD  3 роки тому +4

      *cough* if you don't have premium it's better than command line burp intruder, it's not speed limited
      Wow what a weird cough, covid amiright?

  • @ricardotech
    @ricardotech 3 роки тому +2

  • @saikiranlingadally1036
    @saikiranlingadally1036 3 роки тому

    ❤️

  • @skyawesome7362
    @skyawesome7362 3 роки тому

    The command doesn’t work on mac

    • @InsiderPhD
      @InsiderPhD  3 роки тому

      You need to install ffuf first using the GitHub link :)

  • @MH-tw1qi
    @MH-tw1qi 3 роки тому

    Hmm i will use ffuf instead dirsearch

  • @pianodotexe3852
    @pianodotexe3852 3 роки тому

    Hi mam I know only terminal and cmd what is this looks new..???

    • @InsiderPhD
      @InsiderPhD  3 роки тому +1

      Check out my video on API enumeration to get a better idea of why you might use a tool like ffuf

    • @pianodotexe3852
      @pianodotexe3852 3 роки тому

      @@InsiderPhD thanks for your reply 🙂 please make a live session on ffuf🔥

    • @InsiderPhD
      @InsiderPhD  3 роки тому +1

      I have insider knowledge that the video you seek is on it's way but by another creator ;)

  • @sechunter1903
    @sechunter1903 3 роки тому

    😍 😛

  • @user-dn1oh3jf3g
    @user-dn1oh3jf3g 2 роки тому

    hgyug

  • @abelimathiasi7509
    @abelimathiasi7509 2 роки тому

    25+ mins and i ddnt even get to know what you where teaching ... i cnt even see the help menu of the TOOL SHAME ON YOU .....

  • @logmantarig
    @logmantarig 3 роки тому

    This actually an Awesome video and great tool with an invaluable information thanks a lot, probably dislikers are Gobuster users.