Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
feroxfuzz — Costruisci fuzzer HTTP black-box struttura-aware in Rust con mutatori, scheduler, observer, decisori e processori componibili per test web e API personalizzati. | Kitploit
Strumenti/GitHubGitHub/epi052/feroxfuzz
Test di Sicurezza delle APISicurezza WebFuzzingUtilità e Framework
GitHubepi052/feroxfuzz

feroxfuzz

Costruisci fuzzer HTTP black-box struttura-aware in Rust con mutatori, scheduler, observer, decisori e processori componibili per test web e API personalizzati.

Vedi Repository
2231957 mesi faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi


🚀 FeroxFuzz 🚀

Una libreria di fuzzing HTTP structure-aware


🤔 Un altro ferox? perché? 🤔

Tranquillo, non è un altro strumento a riga di comando, è una libreria! 😁

Più precisamente, FeroxFuzz è una libreria di fuzzing HTTP structure-aware.

L'obiettivo principale nello scrivere FeroxFuzz era spostare alcune parti fondamentali fuori da feroxbuster e in un luogo dove potessero essere generalmente utili per altre persone. In questo modo, la mia speranza è che chiunque voglia scrivere strumenti web e/o fuzzer web usa-e-getta in Rust possa farlo con il minimo sforzo.

Progettazione

La progettazione complessiva di FeroxFuzz deriva da LibAFL. FeroxFuzz implementa la maggior parte dei componenti elencati in LibAFL: A Framework to Build Modular and Reusable Fuzzers (pre-print). Quando FeroxFuzz si discosta, è tipicamente dovuto al supporto del codice asincrono.

Simile a LibAFL, FeroxFuzz è una libreria di fuzzing componibile. Tuttavia, a differenza di LibAFL, FeroxFuzz è focalizzata esclusivamente sul black box HTTP fuzzing.

Flusso di esecuzione del fuzz-loop

Di seguito è riportata una rappresentazione visiva dei diversi componenti, hook e flusso di controllo impiegati da FeroxFuzz.

fuzz-flow

🚧 Attenzione: Lavori in corso 🚧

FeroxFuzz è molto capace ed è stato creato per soddisfare tutte le esigenze pianificate per un nuovo feroxbuster. Tuttavia, mi aspetto ancora che l'API di FeroxFuzz cambi, almeno leggermente, quando inizierà il lavoro sulla nuova versione di feroxbuster.

Finché l'API non si stabilizza, le modifiche breaking potrebbero si verificheranno.

Per iniziare

Il modo più semplice per iniziare è includere FeroxFuzz nel Cargo.toml del tuo progetto.

root@kitploit:~
[dependencies]
feroxfuzz = { version = "1.0.0-rc.13" }

Documentazione

Oltre alla cartella examples/, la documentazione delle API contiene un'ampia documentazione dei componenti insieme a esempi del loro utilizzo.

  • Documentazione API di FeroxFuzz: la documentazione API di FeroxFuzz, generata automaticamente dai doc comments presenti in questo repository.
  • Esempi Ufficiali: gli esempi dedicati ed eseguibili di FeroxFuzz, ottimi per approfondire concetti specifici e ampiamente commentati.

Esempio

L'esempio seguente (examples/async-simple.rs) mostra il minimo indispensabile per scrivere un fuzzer usando FeroxFuzz.

Se si utilizza il codice sorgente, l'esempio può essere eseguito dalla directory feroxfuzz/ usando il seguente comando:

nota: a meno che tu non abbia un webserver in esecuzione sulla tua macchina @ porta 8000, dovrai modificare il target passato in Request::from_url

root@kitploit:~
cargo run --example async-simple
root@kitploit:~
#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    // create a new corpus from the given list of words
    let words = Wordlist::from_file("./examples/words")?
        .name("words")
        .build();

    // pass the corpus to the state object, which will be shared between all of the fuzzers and processors
    let mut state = SharedState::with_corpus(words);

    // bring-your-own client, this example uses the reqwest library
    let req_client = reqwest::Client::builder().build()?;

    // with some client that can handle the actual http request/response stuff
    // we can build a feroxfuzz client, specifically an asynchronous client in this
    // instance.
    //
    // feroxfuzz provides both a blocking and an asynchronous client implementation
    // using reqwest. 
    let client = AsyncClient::with_client(req_client);

    // ReplaceKeyword mutators operate similar to how ffuf/wfuzz work, in that they'll
    // put the current corpus item wherever the keyword is found, as long as its found
    // in data marked fuzzable (see ShouldFuzz directives below)
    let mutator = ReplaceKeyword::new(&"FUZZ", "words");

    // fuzz directives control which parts of the request should be fuzzed
    // anything not marked fuzzable is considered to be static and won't be mutated
    //
    // ShouldFuzz directives map to the various components of an HTTP request
    let request = Request::from_url(
        "http://localhost:8000/?admin=FUZZ",
        Some(&[ShouldFuzz::URLParameterValues]),
    )?;

    // a `StatusCodeDecider` provides a way to inspect each response's status code and decide upon some Action
    // based on the result of whatever comparison function (closure) is passed to the StatusCodeDecider's
    // constructor
    //
    // in plain english, the `StatusCodeDecider` below will check to see if the request's http response code
    // received is equal to 200/OK. If the response code is 200, then the decider will recommend the `Keep`
    // action be performed. If the response code is anything other than 200, then the recommendation will
    // be to `Discard` the response.
    //
    // `Keep`ing the response means that the response will be allowed to continue on for further processing
    // later in the fuzz loop.
    let decider = StatusCodeDecider::new(200, |status, observed, _state| {
        if status == observed {
            Action::Keep
        } else {
            Action::Discard
        }
    });

    // a `ResponseObserver` is responsible for gathering information from each response and providing
    // that information to later fuzzing components, like Processors. It knows things like the response's
    // status code, content length, the time it took to receive the response, and a bunch of other stuff.
    let response_observer: ResponseObserver<AsyncResponse> = ResponseObserver::new();

    // a `ResponseProcessor` provides access to the fuzzer's instance of `ResponseObserver`
    // as well as the `Action` returned from calling `Deciders` (like the `StatusCodeDecider` above).
    // Those two objects may be used to produce side-effects, such as printing, logging, calling out to
    // some other service, or whatever else you can think of.
    let response_printer = ResponseProcessor::new(
        |response_observer: &ResponseObserver<AsyncResponse>, action, _state| {
            if let Some(Action::Keep) = action {
                println!(
                    "[{}] {} - {} - {:?}",
                    response_observer.status_code(),
                    response_observer.content_length(),
                    response_observer.url(),
                    response_observer.elapsed()
                );
            }
        },
    );

    // `Scheduler`s manage how the fuzzer gets entries from the corpus. The `OrderedScheduler` provides
    // in-order access of the associated `Corpus` (`Wordlist` in this example's case)
    let scheduler = OrderedScheduler::new(state.clone())?;

    // the macro calls below are essentially boilerplate. Whatever observers, deciders, mutators,
    // and processors you want to use, you simply pass them to the appropriate macro call and
    // eventually to the Fuzzer constructor.
    let deciders = build_deciders!(decider);
    let mutators = build_mutators!(mutator);
    let observers = build_observers!(response_observer);
    let processors = build_processors!(response_printer);

    let threads = 40;  // number of threads to use for the fuzzing process

    // the `Fuzzer` is the main component of the feroxfuzz library. It wraps most of the other components 
    // and takes care of the actual fuzzing process.
    let mut fuzzer = AsyncFuzzer::new(threads)
        .client(client)
        .request(request)
        .scheduler(scheduler)
        .mutators(mutators)
        .observers(observers)
        .processors(processors)
        .deciders(deciders)
        .post_loop_hook(|state| {
            // this closure is called after each fuzzing loop iteration completes.
            // it's a good place to do things like print out stats
            // or do other things that you want to happen after each
            // full iteration over the corpus
            println!("\n•*´¨`*•.¸¸.•* Finished fuzzing loop •*´¨`*•.¸¸.•*\n");
            println!("{state:#}");
        })
        .build();

    // the fuzzer will run until it iterates over the entire corpus once
    fuzzer.fuzz_once(&mut state).await?;

    println!("{state:#}");

    Ok(())
}

Il fuzzer sopra produrrebbe qualcosa di simile a quanto mostrato di seguito.

root@kitploit:~
[200] 815 - http://localhost:8000/?admin=Ajax - 840.985µs
[200] 206 - http://localhost:8000/?admin=Al - 4.092037ms
----8<----
SharedState::{
  Seed=24301
  Rng=RomuDuoJrRand { x_state: 97704, y_state: 403063 }
  Corpus[words]=Wordlist::{len=102774, top-3=[Static("A"), Static("A's"), Static("AMD")]},
  Statistics={"timeouts":0,"requests":102774.0,"errors":44208,"informatives":3626,"successes":29231,"redirects":25709,"client_errors":18195,"server_errors":26013,"redirection_errors":0,"connection_errors":0,"request_errors":0,"start_time":{"secs":1662124648,"nanos":810398280},"avg_reqs_per_sec":5946.646301595066,"statuses":{"500":14890,"201":3641,"307":3656,"203":3562,"101":3626,"401":3625,"207":3711,"308":3578,"300":3724,"404":3705,"301":3707,"302":3651,"304":3706,"502":3682,"402":3636,"200":3718,"503":3762,"400":3585,"501":3679,"202":3659,"205":3680,"206":3676,"204":3584,"403":3644,"303":3687}}
}

🤓 Progetti che usano FeroxFuzz 🤓


chameleon

Contributori ✨

Grazie a queste meravigliose persone (chiave emoji):

iustin24
iustin24

💻
andreademurtas
andreademurtas

💻
Mieszko Grodzicki
Mieszko Grodzicki

💻 🚇

Questo progetto segue la specifica all-contributors. Contributi di ogni tipo sono i benvenuti!

Scarica lo strumento