Assuming that our login or password reset form isn’t AJAX-y:
Here $POST_VARS
should look something like username=FUZZ&email=FUZZ@example.com&password=1234&cpassword=1234
. The -mr
flag instructs ffuf to filter on page text for a “successful hit”; -s
supresses all output except successful fuzzes (as defined by -mr
).