Operator tip · ffuf

Filter smart

ffuf -u URL/FUZZ -w wordlist -mc 200,204,301,302,403 -fs <size> to drop boring catch-all responses.

med content-discoveryffuffuzzing
/ffuf/ · /tips/ffuf-filter-smart/

Guide

ffuf without filters is a wall of identical 200s from a catch-all router. Smart match/filter flags turn fuzzing into signal.

Why it matters

Many apps return the same soft-404 body for every unknown path. Matching only interesting status codes and filtering by response size (-fs) or words (-fw) surfaces the real directories — the same instinct as the hidden-dir lab.

How-to

# Baseline: note the size of a nonsense path
ffuf -u http://TARGET/FUZZ -w wordlist.txt -mc 200,204,301,302,403 -fs 12345

# Recurse carefully on finds
ffuf -u http://TARGET/FUZZ -w wordlist.txt -mc 200,301,302,403 -e .php,.txt,.bak

# Filter by words if size wobbles
ffuf -u http://TARGET/FUZZ -w wordlist.txt -fw 42