Skip to contentExploitQuest

Lesson 1 of 2 in ffuf · 3 min left in this chapter

The Anomaly Is the Answer

Content discovery is not about finding a 200. It is about noticing the one response that is unlike all the others.

2 min read

Not yet reviewed

Content discovery asks a server for thousands of paths and reports what came back. Beginners look for a 200 and stop. That is usually the wrong filter, because a well-configured server returns 404 for everything that does not exist and the interesting result is rarely a clean success.

What you are actually looking for

What people filter for

Status: 200

What is usually interesting

403 - it exists, and you are not allowed. Something is there.
401 - it exists and wants credentials. Now you know it exists.
500 - you broke something, which means you reached something.
302 - it answered and sent you somewhere. Where?
A 404 whose SIZE differs from every other 404.

The last one is the sharpest. If every missing page returns the same 404 body, a 404 of a different length is not a missing page — it is a different code path.

Note

This is the same reasoning as reading an access log in the forensics course, and as nmap's filtered ports: the finding is the thing that does not match its neighbours, rather than the thing that matches a rule you brought with you.

Trying it

Your turn

Fuzz brightpath.example with the wordlist in words.txt. One path answers differently from the rest — find it.

you@practice
Practice shell — nothing here is real. Type 'help' to begin.

Wordlists decide the result

A content discovery run is only as good as its list. A generic list finds generic things; a list built from the target — words from their own pages, their product names, their developers' naming habits — finds the things nobody else has found.

Take care

Fuzzing is thousands of requests. Against somebody else's production server that is a load you have no permission to impose, and on a small host it is indistinguishable from an attempt to knock it over. Rate-limit yourself, and do not run it at all outside a scope you have in writing.

Every missing path returns a 404 of exactly 162 bytes. One returns a 404 of 2,317 bytes. What is that?