Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
ffufw — ペネトレーションテスト向けに、マルチスレッドのffuf実行、テクノロジー対応ワードリスト、エンドポイントフィルタリング、WAF除外、gowitnessスクリーンショットを使用して、ウェブコンテンツの発見とディレクトリのブルートフォースを自動化します。 | Kitploit
ツール/GitHubGitHub/puzzlepeaches/ffufw
偵察情報収集ウェブセキュリティファジングペネトレーションテスト
GitHubpuzzlepeaches/ffufw

ffufw

ペネトレーションテスト向けに、マルチスレッドのffuf実行、テクノロジー対応ワードリスト、エンドポイントフィルタリング、WAF除外、gowitnessスクリーンショットを使用して、ウェブコンテンツの発見とディレクトリのブルートフォースを自動化します。

リポジトリを見る
14610216ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

ffufw

特別なソースを添えたffuf

インストール

go install github.com/puzzlepeaches/ffufw@latest

なぜ?

ffufw は、ディレクトリのブルートフォースをより簡単かつインテリジェントにするための ffuf のラッパーです。このツールには以下の機能があります:

  • URLリストに対するffufコマンドのマルチスレッド実行
  • gowappalyzerを使用したテクノロジーの動的検出
  • 検出されたテクノロジーに基づくffufコマンドの動的生成(カスタムワードリストと拡張子を含む)
  • ffuf出力を解析して不要なものを除去し、潜在的に関心のあるエンドポイントを特定する
  • 発見されたURLをレビュー用にgowitnessに渡す機能
  • WAFを利用するURLをスキャンから除外する機能

はじめに

このプロジェクトではGoのインストールが必要です。インストール手順はこちらにあります。または、次のコマンドとリポジトリを使用してGoをすばやくインストールすることもできます:

wget -q -O - https://git.io/vQhTU | bash

次のコマンドでツールをインストールします:

go install github.com/puzzlepeaches/ffufw@latest

このツールを実行するには、次のツールが必要です:

  • ffuf
  • ffufPostProcessing

次のコマンドで要件をインストールします:

go install github.com/Damian89/ffufPostprocessing@latest
go install github.com/ffuf/ffuf/v2@latest

ワードリストは、システム上にまだ存在しない場合、初回実行時に ~/.ffufw/wordlists/ ディレクトリにダウンロードされます。ダウンロードされるすべてのワードリストの一覧については、cmd/wordlists/storage.go を参照してください。単一のカスタムワードリストもサポートされており、-w フラグを使用して指定できます。

使用方法

このツールのヘルプメニューは次のとおりです:

ffuf with that special sauce

Usage:
  ffufw [flags] -i <input file> -o <output directory>
  ffufw [command]

Available Commands:
  help        Help about any command
  version     Print the version number of generated code example

Flags:
  -t, --concurrency int             Set the concurrency level for scanning (default 3)
  -c, --config string               Specify the config file for FFUF (default "~/.ffufrc")
  -w, --custom-wordlist string      Specify a custom wordlist to use for scanning. This disable technology detection and pre-defined wordlists for all URLs.
  -e, --exclude-waf                 Exclude WAFs from the scans.
      --ffuf string                 Specify the path to the ffuf binary (default "ffuf")
      --ffufPostprocessing string   Specify the path to the ffufPostprocessing binary (default "ffufPostprocessing")
  -g, --gowitness string            Specify the address for the gowitness API. Ensure format is http://<ip>:<port>
  -h, --help                        help for ffufw
  -i, --input string                Specify the list of URLs to scan
  -o, --output string               Specify the output directory for FFUF results
  -q, --quiet                       Enable silent mode (no additional information printed)
  -r, --replay-proxy string         Specify the address for a replay proxy. Ensure format is http://<ip>:<port>
  -v, --verbose                     Enable verbose mode (print additional information)

Use "ffufw [command] --help" for more information about a command.

使用例

カスタムffuf設定ファイルとverbose出力を使用した、ツールの非常に基本的な使い方:

ffufw -o /tmp/output/ -i /tmp/targets.txt -c /opt/.ffufrc -v

出力をgowitnessに送る基本的な使い方:

ffufw -o /tmp/output/ -i /tmp/targets.txt -g http://127.0.0.1:9999

カスタムのffufおよびffufPostprocessingバイナリを使用する場合:

ffufw --ffuf /usr/local/bin/ffuf --ffufPostprocessing /usr/local/bin/ffufPostprocessing -o /tmp/output/ -i /tmp/targets.txt

カスタムの同時実行数(一度にスキャンするURLの数)を使用する場合:

ffufw -o /tmp/output/ -i /tmp/targets.txt -c /opt/.ffufrc -t 5

gowitness、verbose出力、WAF除外を使用した基本的な使い方:

ffufw -o /tmp/output/ -i /tmp/urls.txt -c /opt/.ffufrc -v -e -g http://127.0.0.1:9000

5スレッドとリプレイプロキシ(Burp、Zapなど)への送信を使用した基本的な使い方:

ffufw -o /tmp/output/ -i /tmp/urls.txt -c /opt/.ffufrc -t 5 -r http://127.0.0.1:8080

TODO

  • テクノロジーチェック追加を容易にサポートするためのリファクタリング
  • 特定のテクノロジーを無視する機能
  • カスタムテクノロジーを追加する機能
  • より良いロギングとエラーハンドリング

参照と謝辞

  • gowappalyzer
  • ffuf
  • ffufPostProcessing
  • gowitness
ツールをダウンロード