Skip to content

Basic webpage endpoint Fuzzer, must supply endpoints for a webpage as Fuzzer does not include a crawler. Will attack endpoints with SQLi and XSS payloads and mutate payloads depending on response. NOTE payloads are live and meant to be used for personal education use ONLY.

Notifications You must be signed in to change notification settings

DavidCJKennedy/MutaFuz

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 

Repository files navigation

fuzzer.py arguments:

1 - App root URL
2 - Display successful payloads, -s to display payloads, -n to not display payloads
3 - Name of .txt containing XSS payloads. 
NOTE: XSS payloads file must be in same directory as fuzzer.py

~~ eg. To execute and display successful payloads
python3 fuzzer.py "http://somedomaintofuzz" -s payloads.txt

~~ eg. To execute and hide successful payloads
python3 fuzzer.py "http://somedomaintofuzz" -n payloads.txt

XSS payload file supplied is named XSS_payloads.txt.
python3 fuzzer.py "http://somedomaintofuzz" -n XSS_payloads.txt

About

Basic webpage endpoint Fuzzer, must supply endpoints for a webpage as Fuzzer does not include a crawler. Will attack endpoints with SQLi and XSS payloads and mutate payloads depending on response. NOTE payloads are live and meant to be used for personal education use ONLY.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages