Summary
In this chapter, we first learned about the basics of fuzzing and the different types of fuzzing attacks. Then, we moved deeper into web application fuzzing and looked at the installation of Wfuzz and ffuf. After that, we performed fuzzing on HTTP request verbs and request URIs. Toward the end of the chapter, we looked at three scenarios: cookie header fuzzing, user-defined cookie header fuzzing, and custom header fuzzing. Having learned about fuzz testing, you can now understand the behavior of a web application, which will help you to find technical as well as logical vulnerabilities. You can use fuzz testing as part of your regular penetration testing while doing bug bounties, or while playing challenging Capture The Flags (CTFs ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access