Skip to main content

Wfuzz - The web fuzzer

Project description

# Wfuzz - The Web Fuzzer

<a href=”https://pypi.python.org/pypi/wfuzz”><img src=”https://img.shields.io/pypi/v/wfuzz.svg”></a> <a href=”https://pypi.python.org/pypi/wfuzz”><img src=”https://img.shields.io/pypi/pyversions/wfuzz.svg”></a> [![Build Status](https://travis-ci.org/xmendez/wfuzz.svg?branch=master)](https://travis-ci.org/xmendez/wfuzz) <a href=”https://codecov.io/github/xmendez/wfuzz”><img src=”https://codecov.io/github/xmendez/wfuzz/coverage.svg?branch=master”></a>

Wfuzz has been created to facilitate the task in web applications assessments and it is based on a simple concept: it replaces any reference to the FUZZ keyword by the value of a given payload.

A payload in Wfuzz is a source of data.

This simple concept allows any input to be injected in any field of an HTTP request, allowing to perform complex web security attacks in different web application components such as: parameters, authentication, forms, directories/files, headers, etc.

Wfuzz is more than a web content scanner:

  • Wfuzz could help you to secure your web applications by finding and exploiting web application vulnerabilities. Wfuzz’s web application vulnerability scanner is supported by plugins.

  • Wfuzz is a completely modular framework and makes it easy for even the newest of Python developers to contribute. Building plugins is simple and takes little more than a few minutes.

  • Wfuzz exposes a simple language interface to the previous HTTP requests/responses performed using Wfuzz or other tools, such as Burp. This allows you to perform manual and semi-automatic tests with full context and understanding of your actions, without relying on a web application scanner underlying implementation.

It was created to facilitate the task in web applications assessments, it’s a tool by pentesters for pentesters ;)

## Installation

To install WFuzz, simply use pip:

` pip install wfuzz ` ## Documentation

Documentation is available at http://wfuzz.readthedocs.io

## Download

Check github releases. Latest is available at https://github.com/xmendez/wfuzz/releases/latest

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

wfuzz-2.4.tar.gz (100.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

wfuzz-2.4-py3-none-any.whl (130.6 kB view details)

Uploaded Python 3

File details

Details for the file wfuzz-2.4.tar.gz.

File metadata

  • Download URL: wfuzz-2.4.tar.gz
  • Upload date:
  • Size: 100.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/1.13.0 pkginfo/1.5.0.1 requests/2.21.0 setuptools/41.0.1 requests-toolbelt/0.9.1 tqdm/4.31.1 CPython/3.6.3

File hashes

Hashes for wfuzz-2.4.tar.gz
Algorithm Hash digest
SHA256 6845c0ce80cb2831ceec4b7e6a9df7904f050ee1c2ba80f64fbc6faf887f1b6b
MD5 e3c986f5ae16f840bdc7297e50061da5
BLAKE2b-256 492fc12021cf5771ce63b22b0033d33e300d8536d9f943f1c039e53a77d3dbd0

See more details on using hashes here.

File details

Details for the file wfuzz-2.4-py3-none-any.whl.

File metadata

  • Download URL: wfuzz-2.4-py3-none-any.whl
  • Upload date:
  • Size: 130.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/1.13.0 pkginfo/1.5.0.1 requests/2.21.0 setuptools/41.0.1 requests-toolbelt/0.9.1 tqdm/4.31.1 CPython/3.6.3

File hashes

Hashes for wfuzz-2.4-py3-none-any.whl
Algorithm Hash digest
SHA256 d7b8a9f6a27350ee63015bc7652cc0e138a5d9012a0afd9490fab03e74bd598a
MD5 9df873e1bebc6ea7573d215635bc2f88
BLAKE2b-256 6c56086061245aed94e4c9b915b78facd3c1da23ad5408fa6195f839fc67622d

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page