4.2 KiB
Fuzzer — HTTP/AI Adversarial Testing Tool
CLI fuzzer for authorized security testing of HTTP endpoints and AI/LLM APIs. Put {{FUZZ}} anywhere in a request and it handles the rest: auth flows, payload delivery, response analysis, and reporting.
Install
pip install requests pyyaml
Quick Start
# Generate starter configs
python fuzzer.py --gen-templates configs
# Run against a target
python fuzzer.py -c configs/simple_post.yml -w wordlists/payloads.txt -o results.log
# Single payload
python fuzzer.py -u https://api.example.com/query -b '{"q": "{{FUZZ}}"}' -p "test payload"
Placeholders
| Placeholder | Replaced with |
|---|---|
{{FUZZ}} |
Each payload from your wordlist |
{{AUTH}} |
Bearer token after the auth step runs |
{{KEY}} |
Any key from your vars file — {{TOKEN}}, {{USERNAME}}, etc. |
Put them anywhere: URL, headers, body.
Config File
name: "My Test"
auth:
url: "https://auth.example.com/oauth2/token"
token_field: "access_token"
cache: 280
request:
url: "https://api.example.com/v1/query"
method: POST
headers:
Authorization: "Bearer {{AUTH}}"
Content-Type: "application/json"
body: '{"prompt": "{{FUZZ}}"}'
fuzz_encoding: json
settings:
timeout: 30
delay: 0.1
Vars File
A flat KEY=VALUE file. Keeps credentials out of configs.
TOKEN=your-token-here
USERNAME=testuser
PASS=testpass
Pass with -e configs/vars.env or let it auto-discover vars.env.
Key Flags
-w FILE Wordlist (one payload per line)
-p TEXT Single payload
-c FILE Config file
-u URL Target URL (CLI mode)
-b BODY Request body template
-H 'Name: V' Add header (repeatable)
-e FILE Vars file
-o FILE Output log (default: fuzzer_output.log)
--threads N Concurrent workers (default: 1)
--delay N Seconds between requests
--proxy URL Route through proxy (e.g. Burp: http://127.0.0.1:8080)
--skip N Skip first N payloads (resume)
--max N Stop after N payloads
--report FILE Write HTML/JSON/CSV report
--debug Show full request/response exchange
Wordlist Organization
Any flat text file works as a wordlist (one payload per line, # for comments). You can organize them by category or test type manually — the fuzzer takes one wordlist at a time via -w.
Authentication
Supports OAuth2 client credentials, session/cookie auth, API key headers, and custom auth flows. The {{AUTH}} placeholder is auto-filled after each auth cycle, and tokens are cached for the duration specified in auth.cache.
See configs/oauth2.yml and configs/session_auth.yml for examples.
Response Flagging
Flag responses by status code, body content, or size:
--flag-status 200 403 # Flag these status codes
--flag-contains "error" # Flag responses containing text
--flag-not-contains "deny" # Flag responses missing text
--flag-size-min 1000 # Flag responses over 1000 bytes
Flagged responses are highlighted in terminal output and separated in reports.
Log Analysis
Analyze an existing log file without re-running the fuzzer:
python fuzzer.py --analyze results.log
python fuzzer.py --analyze results.log --analyze-html report.html
Multi-Turn Sequences
Chain requests for conversation-based testing:
python fuzzer.py --sequences configs/sequences_example.json --sequence "jailbreak-chain" -c configs/simple_post.yml
Other Features
- OpenAPI discovery:
--openapi spec.yaml— parse endpoints, auto-generate configs - Burp import:
--burp-import burp-export.xml— use a Burp-captured request as the target - Payload mutation:
--mutate encoding— auto-generate encoding variants (base64, URL, unicode, etc.) - Combinator:
--prefix-file p.txt --suffix-file s.txt --combine— combine prefix+payload+suffix - Checkpoint/resume: saves state automatically,
--skip Nto resume - Deduplication:
--dedupe-file results.log— remove duplicate responses from a log - Jitter:
--jitter— randomize timing between requests - UA rotation:
--rotate-ua— cycle User-Agent headers
Authorization
For authorized security testing only. Always obtain written scope authorization before testing any system you don't own.