
Browser based FFUF
A simple browser based FFUF Fuzzer Tool
The problem it solves
Web fuzzing (sending lots of requests to find hidden pages, endpoints, or test login forms) normally requires command-line tools. That means installation, configuration, and knowing the right flags before you can even start. FFUF removes all of that.
How it works
You put FUZZ in a URL, pick or upload a wordlist, and click start. The tool fires requests through a server-side proxy — which means you get real HTTP status codes on every request, on any target, without CORS getting in the way.
Four things it does well
Finding hidden directories and files — 2,800+ built-in paths, organised by category. Admin panels, sensitive files, API endpoints, CMS paths and more.
IDOR testing — generate number ranges in the browser without uploading anything. Check which user IDs actually exist.
POST body fuzzing — inject wordlist entries into request bodies. Works for JSON APIs and HTML forms.
Brute force — combine a body template with a password list. The successful login stands out by status code or response size.
Who it's for
Bug bounty hunters, security researchers, developers who want to test their own apps, and students learning web security.
It's completely free. No account, no limits.
Try it at ffuf.codewithneo.com
About
Whenever I had to use the FFUF fuzzer tool quickly, I had to fire up my Kali Linux environment, which became very time-consuming, so I decided to build this solution as a web based ffuf fuzzer tool

Comment