All resources
Topic

fuzzing

4 resources across 3 kinds

Tools

  1. A Burp Suite extension for API security testing that auto-captures and normalizes API traffic, groups endpoints, and generates fuzzing campaigns covering OWASP API Top 10 issues (BOLA/IDOR, SQLi, XSS, NoSQLi, XXE, JWT abuse, GraphQL abuse, race conditions). It exports to Burp Intruder/Turbo Intruder, Nuclei, and external tools (SQLMap, Dalfox, HTTPX, Katana, FFUF), and is actively maintained (v1.4.15, MIT).

    Open ↗
  2. XSSeractivehigh-riskdual-uselicence

    XSSer (Cross Site Scripter) is an automated framework to detect, exploit and report XSS vulnerabilities in web apps, shipping 1,500+ attack vectors with a context-aware validation engine, WAF bypassers and encoding evasion, injection across GET/POST params, cookies and DOM, and PDF/XML/JSON reporting. Python 3 with CLI and GTK GUI.

    Open ↗

Labs & practice targets

  1. FFUF.mehosted

    Target practice environment for the ffuf web fuzzer.

    Open ↗

References

  1. Automated and manually-curated wordlists for content and subdomain discovery, regenerated monthly (via Commonspeak2 and GitHub Actions) targeting popular internet technologies. Apache-2.0 licensed, served via CDN with a browsable DataTables interface and bulk wget download.

    Open ↗