# wfuzz
[wfuzz](https://github.com/xmendez/wfuzz) fuzzes things.

## Discover subdomains
```
wfuzz -c -w /opt/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u "https://FUZZ.7minsec.com" --sc 200,301,301,401 -Z
```

*Source: [X](https://x.com/gudetama_bf/status/1838481076827885704?s=51).  [This site](https://infinitelogins.com/2020/09/02/bruteforcing-subdomains-wfuzz/) gave me some good ideas as well.*

## Discover Web content
```
wfuzz -c -w /opt/seclists/Discovery/Web-Content/directory-list-2.3-big.txt -u "https://7minsec.com/FUZZ" --sc 200,301,301,401 -Z
```
