Skip to contentExploitQuest

Lesson 2 of 2 in ffuf

Ten Thousand Lines in Your Log

Content discovery is the loudest thing in this course. Here is what it does to the target, and the one shape worth alerting on.

3 min read

Not yet reviewed

A port scan is thousands of packets to ports nothing is listening on. A fuzzing run is thousands of full HTTP requests to an application that answers every one of them — parsing, routing, logging and sometimes querying a database each time.

four seconds of content discovery
198.51.100.44 - - [14/Aug/2026:02:11:03] "GET /admin HTTP/1.1" 404 162
198.51.100.44 - - [14/Aug/2026:02:11:03] "GET /login HTTP/1.1" 404 162
198.51.100.44 - - [14/Aug/2026:02:11:03] "GET /backup HTTP/1.1" 403 94
198.51.100.44 - - [14/Aug/2026:02:11:03] "GET /uploads HTTP/1.1" 404 162
198.51.100.44 - - [14/Aug/2026:02:11:04] "GET /.git HTTP/1.1" 404 162
# ...ten thousand more, one address, same second

Unmissable, and — like a port scan — almost useless as an alert on its own, because every public site receives this continuously from people who have never heard of it.

The shape that is worth waking somebody for

Weather

Ten thousand 404s from one address, then nothing
Requests for /wp-login.php on a site that is not WordPress
A wordlist you recognise, because everybody uses it

Worth a look

A fuzzing run that stops immediately after a non-404
Paths that match YOUR naming, not a public wordlist
The same run repeated from several addresses

The first of those is the tell, and it is the same one the forensics course teaches about scanners: a tool that finds nothing keeps going. A tool that finds something stops, because a person is now looking.

The second is the one that should genuinely worry you. Public wordlists contain public words. Somebody requesting paths that match your internal naming conventions has read something of yours — a JavaScript bundle, a stale sitemap, a public repository — and built a list from it.

What to do about it

Rate-limit by source, and return the same 404 for everything absent
Make sure "forbidden" and "not found" are the same answer where it matters
Serve nothing from a directory listing, ever
Log the 403s and the 500s, and read those rather than the 404s
  1. Line 1Identical 404s are not cosmetic. A 404 whose size varies is what makes the previous lesson's technique work, and it is free to fix.
  2. Line 2A 403 confirms existence. Where existence is itself sensitive — an admin path, another user's resource — return 404 and confirm nothing.
  3. Line 4The 404s are the noise by definition; they are what the scanner got. Everything it *reached* is in the other two.

Take care

Ten thousand requests in four seconds is a load, not just a log entry. On a small host it is indistinguishable from an attempt to take the site down, and that is how it will be described afterwards. Do not run this outside a scope you hold in writing.

A fuzzing run against your site stops abruptly after one 403. What does that suggest?