fm-fsf – Web Application Fuzzer and Data Scraping tool

by Black on June 17, 2009 · 0 comments

in Fuzzing, Penetration Testing

fm-fsf – Freakin’ Simple Fuzzer is built for web applications and data scraping. It is plugin based tool. You can build and add your own plugin.

owasp fm fsf   Web Application Fuzzer and Data Scraping tool

It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.

It’s still in early stage of development. It’s not well tested and I developed it when I need it, so don’t keep your hopes high.

We are all testing this tool weather we can include it in our white hat penetration testing framework.

Use of this tool is when you want to take advantage of RegEx with the full power for scraping data (this is quite useful while exploiting SQL Injections, gathering data, looking for some hidden resource or trying to enumerate all valid “user id”s) simple to run and simple which makes it easy to write your own fuzzing modules with simple and compact .NET code .

This tool is for advance users or advance fuzzers who know how to use fuzzers and want more to explore more.

Tips to use fuzzers – fm-fsf:
Create a sqli.txt file and directories.txt and remember to change it in command while running it.

For beginners, try some other fuzzer and then use this one. You will have a clear idea.

To create or change config of fm-fsf fuzzer there are two file
1.FSF.exe.config
2.FSF.vshost.exe.config

Make changes as per your requirement and run the tool. While using it in windows if you get windows error message popup donot panic it a simple error message just say dont send .

Download fm-fsf fuzzer here

Related External Links

  • Gone in 60 Days: Citi and Bank of America Won’t Live to See May
Searches leading to this post:
backtrack web fuzzer, freaking simple fuzzer, Web based data scraping tools, web based data scrapping tools free

Related Posts

Previous post:

Next post: