Browser based FFUF

A simple browser based FFUF Fuzzer Tool

Visit Website
August 22, 2026 I'm launching FFUF today — a free browser-based web fuzzing tool.

The problem it solves

Web fuzzing (sending lots of requests to find hidden pages, endpoints, or test login forms) normally requires command-line tools. That means installation, configuration, and knowing the right flags before you can even start. FFUF removes all of that.

How it works

You put FUZZ in a URL, pick or upload a wordlist, and click start. The tool fires requests through a server-side proxy — which means you get real HTTP status codes on every request, on any target, without CORS getting in the way.

Four things it does well

Finding hidden directories and files — 2,800+ built-in paths, organised by category. Admin panels, sensitive files, API endpoints, CMS paths and more.

IDOR testing — generate number ranges in the browser without uploading anything. Check which user IDs actually exist.

POST body fuzzing — inject wordlist entries into request bodies. Works for JSON APIs and HTML forms.

Brute force — combine a body template with a password list. The successful login stands out by status code or response size.

Who it's for

Bug bounty hunters, security researchers, developers who want to test their own apps, and students learning web security.

It's completely free. No account, no limits.

Try it at ffuf.codewithneo.com

Comment

About

Whenever I had to use the FFUF fuzzer tool quickly, I had to fire up my Kali Linux environment, which became very time-consuming, so I decided to build this solution as a web based ffuf fuzzer tool