{"id":15264,"date":"2021-03-12T15:48:57","date_gmt":"2021-03-12T22:48:57","guid":{"rendered":"https:\/\/xerosecurity.com\/wordpress\/?page_id=15264"},"modified":"2024-09-17T14:21:57","modified_gmt":"2024-09-17T21:21:57","slug":"fuzzer-add-on-v1-0-documentation","status":"publish","type":"page","link":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/","title":{"rendered":"Fuzzer Add-on v1.0 Documentation"},"content":{"rendered":"<p>Automatically fuzz for OWASP TOP 10 vulnerabilities and discover hidden content easily with the new Sn1per Professional Fuzzer Add-on!<\/p>\n<h4>Features<\/h4>\n<hr \/>\n<ul>\n<li>Automatically fuzz dynamic URL\u2019s for OWASP TOP 10 vulnerabilities.<\/li>\n<li>Discover hidden content in a target environment.<\/li>\n<li>Spider all URL\u2019s within a target environment.<\/li>\n<li>Single &amp; built-in multi target selections.<\/li>\n<li>Customized wordlist selections and options via the GUI.<\/li>\n<li>HTML and text based reports for all tools (ie. Black Widow, InjectX, SQLMap, Arachni, FFuf, Dirsearch, Gobuster)<\/li>\n<li>Reporting of all output via the <a href=\"https:\/\/sn1persecurity.com\/wordpress\/product\/command-execution-add-on-v2\/\">Command Execution Add-on<\/a>.<\/li>\n<\/ul>\n<h4>Adding Custom Wordlists<\/h4>\n<hr \/>\n<p>To add custom wordlists, add any .txt files to the following directory:<\/p>\n<pre>\/usr\/share\/sniper\/wordlists\/custom\/*.txt<\/pre>\n<h4>Usage<\/h4>\n<hr \/>\n<h5>Discover Hidden Content<\/h5>\n<p>To fuzz a specific URL to discover hidden files and folders, do the following:<\/p>\n<ol>\n<li>Click on any workspace from the Workspace Navigator<\/li>\n<li>Scroll down and click &#8220;Fuzzer&#8221; menu to access the Fuzzer Add-on<\/li>\n<li>Enter the starting URL you want to brute force in the URL field<\/li>\n<li>Select a wordlist to use from the &#8220;Wordlist&#8221; menu<\/li>\n<li>Select a program to use (ie. Gobuster, Dirsearch, Ffuf)<\/li>\n<li>Click the &#8220;Run&#8221; button to begin the scan<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-15267\" src=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer1.png\" alt=\"\" width=\"1659\" height=\"413\" srcset=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer1.png 1659w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer1-600x149.png 600w\" sizes=\"auto, (max-width: 1659px) 100vw, 1659px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-15266\" src=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer1b.png\" alt=\"\" width=\"1224\" height=\"323\" srcset=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer1b.png 1224w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer1b-600x158.png 600w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer1b-300x79.png 300w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer1b-1024x270.png 1024w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer1b-768x203.png 768w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer1b-400x106.png 400w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer1b-800x211.png 800w\" sizes=\"auto, (max-width: 1224px) 100vw, 1224px\" \/><\/p>\n<h5>Crawl\/Spider All URL&#8217;s<\/h5>\n<p>To crawl\/spider a website to discover all URL&#8217;s, do the following:<\/p>\n<ol>\n<li>Click on any workspace from the Workspace Navigator<\/li>\n<li>Scroll down and click &#8220;Fuzzer&#8221; menu to access the Fuzzer Add-on<\/li>\n<li>Enter the starting URL you want to spider in the URL field<\/li>\n<li>Select &#8220;BlackWidow&#8221; from the &#8220;Program&#8221; menu<\/li>\n<li>Click the &#8220;Run&#8221; button to begin the scan<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-15272\" src=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer2.png\" alt=\"\" width=\"1659\" height=\"411\" srcset=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer2.png 1659w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer2-600x149.png 600w\" sizes=\"auto, (max-width: 1659px) 100vw, 1659px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-15271\" src=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer2b.png\" alt=\"\" width=\"1484\" height=\"999\" srcset=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer2b.png 1484w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer2b-600x404.png 600w\" sizes=\"auto, (max-width: 1484px) 100vw, 1484px\" \/><\/p>\n<h5>Fuzz All Dynamic URL&#8217;s for OWASP Top 10 Vulnerabilities<\/h5>\n<p>To fuzz all dynamic URL&#8217;s for OWASP Top 10 vulnerabilities, do the following:<\/p>\n<ol>\n<li>Click on any workspace from the Workspace Navigator<\/li>\n<li>Scroll down and click &#8220;Fuzzer&#8221; menu to access the Fuzzer Add-on<\/li>\n<li>Select a URL list to fuzz from the &#8220;URL List&#8221; menu (ie. target.com_port-dynamic-sorted.txt)<\/li>\n<li>Select &#8220;InjectX&#8221; from the &#8220;Program&#8221; menu<\/li>\n<li>Click the &#8220;Run&#8221; button to begin the scan<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-15275\" src=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3.png\" alt=\"\" width=\"1658\" height=\"413\" srcset=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3.png 1658w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3-600x149.png 600w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3-300x75.png 300w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3-1024x255.png 1024w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3-768x191.png 768w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3-1536x383.png 1536w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3-400x100.png 400w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3-800x199.png 800w\" sizes=\"auto, (max-width: 1658px) 100vw, 1658px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-15274\" src=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3b.png\" alt=\"\" width=\"1374\" height=\"982\" srcset=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3b.png 1374w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer3b-600x429.png 600w\" sizes=\"auto, (max-width: 1374px) 100vw, 1374px\" \/><\/p>\n<h5>Run Automated Web Application Scans<\/h5>\n<p>To run automated web application scans against a target website, do the following:<\/p>\n<ol>\n<li>Click on any workspace from the Workspace Navigator<\/li>\n<li>Scroll down and click &#8220;Fuzzer&#8221; menu to access the Fuzzer Add-on<\/li>\n<li>Enter the starting URL you want to spider in the URL field<\/li>\n<li>Select &#8220;Nikto&#8221;, &#8220;Arachni&#8221; or &#8220;SQLMap&#8221; from the &#8220;Program&#8221; menu<\/li>\n<li>Click the &#8220;Crawl&#8221; checkbox to spider all URL&#8217;s<\/li>\n<li>Click the &#8220;Run&#8221; button to begin the scan<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-15278\" src=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer4.png\" alt=\"\" width=\"1657\" height=\"414\" srcset=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer4.png 1657w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer4-600x150.png 600w\" sizes=\"auto, (max-width: 1657px) 100vw, 1657px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-15279 size-full\" src=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer4b.png\" alt=\"\" width=\"1413\" height=\"641\" srcset=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer4b.png 1413w, https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-fuzzer4b-600x272.png 600w\" sizes=\"auto, (max-width: 1413px) 100vw, 1413px\" \/><\/p>\n<h4>Misc Usage Notes<\/h4>\n<hr \/>\n<p>When using the Fuzzer Add-on, it&#8217;s important to keep the following in mind:<\/p>\n<ul>\n<li>Only the URL field OR the URL List field can be selected at one time. If URL List does not equal &#8220;NA&#8221;, the URL List will be used by default.<\/li>\n<li>To fuzz all web hosts in a workspace, you can select the &#8216;webhosts-sorted.txt&#8217; file in the URL List drop down menu.<\/li>\n<li>To specify extensions to scan for, use ext, ext2, ext3 for Gobuster and Dirsearch. For FFuf, use .ext, .ext2, .ext3<\/li>\n<li>The &#8220;Autotune&#8221; option only applies to Gobuster and FFuf. This will auto filter results based on heuristics.<\/li>\n<li>The &#8220;Crawl&#8221; option only applies to both SQLMap and Arachni to increase the crawl\/spider limits.<\/li>\n<li>All output from all tools is stored under \/usr\/share\/sniper\/loot\/workspace\/&lt;WORKSPACE&gt;\/web\/. There is also a link within the fuzzer addon for convenience.<\/li>\n<li>HTML reports are produced for both Arachni and FFuf scans.<\/li>\n<li>Use the built-in URL Lists to automatically select URL lists based on previous scans. You can also add .txt files to your \/usr\/share\/sniper\/loot\/workspace\/&lt;WORKSPACE&gt;\/web\/ directory to automatically import them.<\/li>\n<li>You can also use the &#8220;FUZZ&#8221; keyword in the URL field when using FFuf to select a specific location to begin fuzzing (ie. https:\/\/target.com\/url.php?file=FUZZ).<\/li>\n<\/ul>\n<h4><a href=\"https:\/\/sn1persecurity.com\/wordpress\/documentation\/\">Back to Main Documentation<\/a><\/h4>\n","protected":false},"excerpt":{"rendered":"<p>Automatically fuzz for OWASP TOP 10 vulnerabilities and discover hidden content easily with the new Sn1per Professional Fuzzer Add-on! Features Automatically fuzz dynamic URL\u2019s for OWASP TOP 10 vulnerabilities. Discover\u2026<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"footnotes":""},"class_list":["post-15264","page","type-page","status-publish","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.9 - aioseo.com -->\n\t<meta name=\"description\" content=\"Set up Sn1per&#039;s Fuzzer add-on for automated web fuzzing \u2014 discover hidden endpoints, parameters, and injection points across your full attack surface.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.9\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Sn1perSecurity\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Sn1per Fuzzer Add-on \u2014 Web Fuzzing Setup &amp; Usage\" \/>\n\t\t<meta property=\"og:description\" content=\"Set up Sn1per&#039;s Fuzzer add-on for automated web fuzzing \u2014 discover hidden endpoints, parameters, and injection points across your full attack surface.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/10\/Sn1perSecurity-Attack-Surface-Management-header2.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/10\/Sn1perSecurity-Attack-Surface-Management-header2.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-03-12T22:48:57+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-09-17T21:21:57+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Sn1persecurity-105784611869093\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@sn1persecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Sn1per Fuzzer Add-on \u2014 Web Fuzzing Setup &amp; Usage\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Set up Sn1per&#039;s Fuzzer add-on for automated web fuzzing \u2014 discover hidden endpoints, parameters, and injection points across your full attack surface.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@sn1persecurity\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/10\/Sn1perSecurity-Attack-Surface-Management-header2.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/fuzzer-add-on-v1-0-documentation\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/fuzzer-add-on-v1-0-documentation\\\/#listItem\",\"name\":\"Fuzzer Add-on v1.0 Documentation\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/fuzzer-add-on-v1-0-documentation\\\/#listItem\",\"position\":2,\"name\":\"Fuzzer Add-on v1.0 Documentation\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/#organization\",\"name\":\"Sn1perSecurity\",\"description\":\"Get an attacker's view of your organization with our all-in-one offensive security platform\",\"url\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/\",\"email\":\"support@sn1persecurity.com\",\"foundingDate\":\"2021-10-05\",\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"value\":2},\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/wp-content\\\/uploads\\\/2022\\\/06\\\/Sn1perwhiteandcircleicontwitter.jpg\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/fuzzer-add-on-v1-0-documentation\\\/#organizationLogo\",\"width\":500,\"height\":500,\"caption\":\"Sn1perSecurity Logo\"},\"image\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/fuzzer-add-on-v1-0-documentation\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Sn1persecurity-105784611869093\",\"https:\\\/\\\/x.com\\\/sn1persecurity\",\"https:\\\/\\\/www.instagram.com\\\/sn1persecurity\",\"https:\\\/\\\/www.youtube.com\\\/sn1persecurity\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/sn1persecurity\\\/\",\"https:\\\/\\\/github.com\\\/1N3\\\/Sn1per\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/fuzzer-add-on-v1-0-documentation\\\/#webpage\",\"url\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/fuzzer-add-on-v1-0-documentation\\\/\",\"name\":\"Sn1per Fuzzer Add-on \\u2014 Web Fuzzing Setup & Usage\",\"description\":\"Set up Sn1per's Fuzzer add-on for automated web fuzzing \\u2014 discover hidden endpoints, parameters, and injection points across your full attack surface.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/fuzzer-add-on-v1-0-documentation\\\/#breadcrumblist\"},\"datePublished\":\"2021-03-12T15:48:57-07:00\",\"dateModified\":\"2024-09-17T14:21:57-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/#website\",\"url\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/\",\"name\":\"Sn1perSecurity\",\"alternateName\":\"Sn1per\",\"description\":\"Get an attacker's view of your organization with our all-in-one offensive security platform\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/sn1persecurity.com\\\/wordpress\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Sn1per Fuzzer Add-on \u2014 Web Fuzzing Setup & Usage","description":"Set up Sn1per's Fuzzer add-on for automated web fuzzing \u2014 discover hidden endpoints, parameters, and injection points across your full attack surface.","canonical_url":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/sn1persecurity.com\/wordpress#listItem","position":1,"name":"Home","item":"https:\/\/sn1persecurity.com\/wordpress","nextItem":{"@type":"ListItem","@id":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/#listItem","name":"Fuzzer Add-on v1.0 Documentation"}},{"@type":"ListItem","@id":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/#listItem","position":2,"name":"Fuzzer Add-on v1.0 Documentation","previousItem":{"@type":"ListItem","@id":"https:\/\/sn1persecurity.com\/wordpress#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/sn1persecurity.com\/wordpress\/#organization","name":"Sn1perSecurity","description":"Get an attacker's view of your organization with our all-in-one offensive security platform","url":"https:\/\/sn1persecurity.com\/wordpress\/","email":"support@sn1persecurity.com","foundingDate":"2021-10-05","numberOfEmployees":{"@type":"QuantitativeValue","value":2},"logo":{"@type":"ImageObject","url":"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2022\/06\/Sn1perwhiteandcircleicontwitter.jpg","@id":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/#organizationLogo","width":500,"height":500,"caption":"Sn1perSecurity Logo"},"image":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/Sn1persecurity-105784611869093","https:\/\/x.com\/sn1persecurity","https:\/\/www.instagram.com\/sn1persecurity","https:\/\/www.youtube.com\/sn1persecurity","https:\/\/www.linkedin.com\/in\/sn1persecurity\/","https:\/\/github.com\/1N3\/Sn1per"]},{"@type":"WebPage","@id":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/#webpage","url":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/","name":"Sn1per Fuzzer Add-on \u2014 Web Fuzzing Setup & Usage","description":"Set up Sn1per's Fuzzer add-on for automated web fuzzing \u2014 discover hidden endpoints, parameters, and injection points across your full attack surface.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/#website"},"breadcrumb":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/#breadcrumblist"},"datePublished":"2021-03-12T15:48:57-07:00","dateModified":"2024-09-17T14:21:57-07:00"},{"@type":"WebSite","@id":"https:\/\/sn1persecurity.com\/wordpress\/#website","url":"https:\/\/sn1persecurity.com\/wordpress\/","name":"Sn1perSecurity","alternateName":"Sn1per","description":"Get an attacker's view of your organization with our all-in-one offensive security platform","inLanguage":"en-US","publisher":{"@id":"https:\/\/sn1persecurity.com\/wordpress\/#organization"}}]},"og:locale":"en_US","og:site_name":"Sn1perSecurity","og:type":"article","og:title":"Sn1per Fuzzer Add-on \u2014 Web Fuzzing Setup &amp; Usage","og:description":"Set up Sn1per's Fuzzer add-on for automated web fuzzing \u2014 discover hidden endpoints, parameters, and injection points across your full attack surface.","og:url":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/","og:image":"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/10\/Sn1perSecurity-Attack-Surface-Management-header2.png","og:image:secure_url":"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/10\/Sn1perSecurity-Attack-Surface-Management-header2.png","og:image:width":1920,"og:image:height":1080,"article:published_time":"2021-03-12T22:48:57+00:00","article:modified_time":"2024-09-17T21:21:57+00:00","article:publisher":"https:\/\/www.facebook.com\/Sn1persecurity-105784611869093","twitter:card":"summary_large_image","twitter:site":"@sn1persecurity","twitter:title":"Sn1per Fuzzer Add-on \u2014 Web Fuzzing Setup &amp; Usage","twitter:description":"Set up Sn1per's Fuzzer add-on for automated web fuzzing \u2014 discover hidden endpoints, parameters, and injection points across your full attack surface.","twitter:creator":"@sn1persecurity","twitter:image":"https:\/\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/10\/Sn1perSecurity-Attack-Surface-Management-header2.png"},"aioseo_meta_data":{"post_id":"15264","title":"Sn1per Fuzzer Add-on \u2014 Web Fuzzing Setup & Usage","description":"Set up Sn1per's Fuzzer add-on for automated web fuzzing \u2014 discover hidden endpoints, parameters, and injection points across your full attack surface.","keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2025-11-01 01:07:19","updated":"2026-06-07 19:13:38","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/sn1persecurity.com\/wordpress\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tFuzzer Add-on v1.0 Documentation\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/sn1persecurity.com\/wordpress"},{"label":"Fuzzer Add-on v1.0 Documentation","link":"https:\/\/sn1persecurity.com\/wordpress\/fuzzer-add-on-v1-0-documentation\/"}],"jetpack_shortlink":"https:\/\/wp.me\/PdnW96-3Yc","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":15174,"url":"https:\/\/sn1persecurity.com\/wordpress\/command-execution-add-on-v2-0-documentation\/","url_meta":{"origin":15264,"position":0},"title":"Command Execution Add-on v2.0 Documentation","author":"xer0dayz","date":"March 2, 2021","format":false,"excerpt":"The Command Execution Add-on v2.0 lets you easily manage your Sn1per Professional instance from a web interface without ever touching the command line. Help Topics Single Target Scan Multi-Target Scan Subnet Scan Custom Target Scan Mass URL Scan Importing URL's Single Target Scan To scan a single target from scratch\u2026","rel":"","context":"Similar post","block_context":{"text":"Similar post","link":""},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/04\/Sn1per-Professional-v9.0-single-target-scan3.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/04\/Sn1per-Professional-v9.0-single-target-scan3.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/04\/Sn1per-Professional-v9.0-single-target-scan3.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/04\/Sn1per-Professional-v9.0-single-target-scan3.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/04\/Sn1per-Professional-v9.0-single-target-scan3.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/04\/Sn1per-Professional-v9.0-single-target-scan3.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":63081,"url":"https:\/\/sn1persecurity.com\/wordpress\/documentation\/configuration\/","url_meta":{"origin":15264,"position":1},"title":"Configuration","author":"xer0dayz","date":"April 25, 2026","format":false,"excerpt":"Documentation\/Configuration Most Sn1per Pro behavior is controlled by two files: \/usr\/share\/sniper\/sniper.conf \u2014 scan engine defaults (threads, DNS, AI, RAG, Burp, notifications, etc.) \/usr\/share\/sniper\/pro\/settings.php \u2014 Pro web UI tunables (license key, install dir, workspace limits, Burp host) Change either file and restart Apache (sudo systemctl reload apache2) to pick up PHP-side\u2026","rel":"","context":"Similar post","block_context":{"text":"Similar post","link":""},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":19930,"url":"https:\/\/sn1persecurity.com\/wordpress\/home\/overview\/","url_meta":{"origin":15264,"position":2},"title":"Overview","author":"xer0dayz","date":"September 12, 2022","format":false,"excerpt":"[vc_row][vc_column][vc_column_text] The ultimate pentesting toolkit. Integrate with the leading commercial and open source security scanners to check for the latest CVEs and vulnerabilities in your environment. [\/vc_column_text][vc_row_inner][vc_column_inner][vc_empty_space height=\"60px\"][\/vc_column_inner][vc_column_inner][vc_column_text] Automate the most powerful tools. Security tools are expensive and time-consuming, but with Sn1per, you can save time by automating the execution\u2026","rel":"","context":"Similar post","block_context":{"text":"Similar post","link":""},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":15285,"url":"https:\/\/sn1persecurity.com\/wordpress\/brute-force-add-on-v1-0-documentation\/","url_meta":{"origin":15264,"position":3},"title":"Brute Force Add-on v1.0 Documentation","author":"xer0dayz","date":"March 13, 2021","format":false,"excerpt":"Check for default and weak credentials across all hosts in your workspace instantly! Features Check for default and weak credentials in a target environment. Single & built-in multi target selections. Customized wordlist selections for usernames and passwords. Automatic brute forcing of all services via BruteX. Reporting of all output via\u2026","rel":"","context":"Similar post","block_context":{"text":"Similar post","link":""},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-brute-force2b.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-brute-force2b.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-brute-force2b.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-brute-force2b.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-brute-force2b.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/sn1persecurity.com\/wordpress\/wp-content\/uploads\/2021\/03\/Sn1per-Professional-v9.0-brute-force2b.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":34090,"url":"https:\/\/sn1persecurity.com\/wordpress\/documentation\/owasp-zap-integration\/","url_meta":{"origin":15264,"position":4},"title":"OWASP ZAP Integration","author":"xer0dayz","date":"September 24, 2024","format":false,"excerpt":"Setup In order to setup OWASP ZAP integration, you will need to have ZAP running on the same host as Sn1per and the http\/https proxy listening on port 8081\/tcp. In addition, you will need to enable the ZAP API service and disable the API key. Next, update the following values\u2026","rel":"","context":"Similar post","block_context":{"text":"Similar post","link":""},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":63083,"url":"https:\/\/sn1persecurity.com\/wordpress\/documentation\/architecture\/","url_meta":{"origin":15264,"position":5},"title":"Architecture","author":"xer0dayz","date":"April 25, 2026","format":false,"excerpt":"Documentation\/Architecture Sn1per Professional 2026 pairs a bash-based scan engine with a modernized PHP web UI on Apache, and optionally integrates with an AI \/ RAG stack for augmented analysis. This doc describes how the components fit together. High-level stack Browser (HTTPS :1337) | v Apache 2.4 --- Digest Auth ---\u2026","rel":"","context":"Similar post","block_context":{"text":"Similar post","link":""},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/pages\/15264","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/comments?post=15264"}],"version-history":[{"count":11,"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/pages\/15264\/revisions"}],"predecessor-version":[{"id":33731,"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/pages\/15264\/revisions\/33731"}],"wp:attachment":[{"href":"https:\/\/sn1persecurity.com\/wordpress\/wp-json\/wp\/v2\/media?parent=15264"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}