一键导入
parameter-fuzzing
Discover hidden parameters, test values, and identify input handling anomalies
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Discover hidden parameters, test values, and identify input handling anomalies
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws
Detect PII, credentials, and corporate sensitive data in API responses, source code, files, headers, and database extracts
Detect and exploit SQL injection vulnerabilities in web application parameters
Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses
Detect and exploit cross-site scripting vulnerabilities in web applications
File upload vulnerability testing — webshells, bypass, path traversal
| name | parameter-fuzzing |
| description | Discover hidden parameters, test values, and identify input handling anomalies |
| origin | RedteamOpencode |
run_tool ffuf (primary), run_tool curl (verification), run_tool arjun (dedicated param discovery, if available)
Unattended runs must never glob, inspect, or depend on host-global wordlist
directories such as /usr/share/seclists/** or /usr/share/wordlists/**.
Those paths trigger external_directory permission prompts and can stall the
runtime. Before using ffuf, create a workspace-local wordlist under the active
engagement directory, for example $DIR/scans/param-wordlist.txt, from the
bounded built-in candidates below plus any endpoint-specific names observed in
the assigned case batch. If a larger corpus is required but no workspace-local
copy already exists, return REQUEUE with that blocker instead of asking for
permission or scanning outside /workspace.
PARAM_WORDLIST="$DIR/scans/param-wordlist.txt"
cat > "$PARAM_WORDLIST" <<'EOF'
id
user
userId
accountId
orderId
debug
test
admin
role
redirect
returnUrl
next
callback
token
csrf
apiKey
query
search
limit
offset
sort
filter
EOF
run_tool curl -s -o /dev/null -w "Code: %{http_code}, Size: %{size_download}" https://TARGET/endpoint
Record baseline response size for -fs filter.
run_tool ffuf -u "https://TARGET/endpoint?FUZZ=test" \
-w "$PARAM_WORDLIST" -fs BASELINE_SIZE
# Or with auto-calibration: -ac
# URL-encoded
run_tool ffuf -u "https://TARGET/endpoint" -X POST -d "FUZZ=test" \
-H "Content-Type: application/x-www-form-urlencoded" \
-w "$PARAM_WORDLIST" -fs BASELINE_SIZE
# JSON
run_tool ffuf -u "https://TARGET/endpoint" -X POST -d '{"FUZZ":"test"}' \
-H "Content-Type: application/json" \
-w "$PARAM_WORDLIST" -fs BASELINE_SIZE
run_tool ffuf -u "https://TARGET/endpoint?id=FUZZ" -w <(seq 1 1000) -fs BASELINE_SIZE # IDOR
printf '%s\n' "'" '"' '<' '>' '../' '{{7*7}}' '${7*7}' 'true' 'false' 'null' > "$DIR/scans/value-fuzz.txt"
run_tool ffuf -u "https://TARGET/endpoint?param=FUZZ" -w "$DIR/scans/value-fuzz.txt" -fs BASELINE_SIZE
# Boolean/toggle: test true,false,1,0,yes,no,null via loop
# Role values: admin,root,user,guest,superadmin via loop
run_tool ffuf -u "https://TARGET/endpoint" -H "FUZZ: test" \
-w "$PARAM_WORDLIST" -fs BASELINE_SIZE
# Common bypass headers:
for header in "X-Forwarded-For: 127.0.0.1" "X-Real-IP: 127.0.0.1" "X-Original-URL: /admin" \
"X-Debug: true" "X-Debug-Mode: 1" "X-Forwarded-Host: localhost"; do
run_tool curl -s -o /dev/null -w "%{http_code} %{size_download}" -H "$header" "https://TARGET/endpoint"
done
run_tool ffuf -u "https://TARGET/endpoint" -b "FUZZ=test" \
-w "$PARAM_WORDLIST" -fs BASELINE_SIZE
run_tool ffuf -u "https://TARGET/endpoint?W1=W2" -w params.txt:W1 -w values.txt:W2 \
-mode clusterbomb -fs BASELINE_SIZE
run_tool arjun -u "https://TARGET/endpoint" -m GET # or POST, JSON
run_tool arjun -u "https://TARGET/endpoint" -w custom_params.txt
run_tool curl -sv "https://TARGET/endpoint?discovered_param=test" 2>&1
diff <(run_tool curl -s "https://TARGET/endpoint") <(run_tool curl -s "https://TARGET/endpoint?param=value")