docs

Hugin Fuzz

Hugin — fuzz

Fuzz at scale. When you have a hunch and need to test it across many values or parameters.

Load the tools

Call tools/list with _meta.bundle = "fuzz". You get ~7 tools, ~7.6k tokens: intruder, ffuzzer, paramhunter, wordlists, bambda, bcheck, upload.

Note: param_discover (hidden parameter fuzzing) is in the bugclass-bac bundle because it's Pro-gated (Feature::Bac). Load fuzz,bugclass-bac if you need it.

Load the skill fragment

Read MCP resource hugin://skill/fuzz for the full workflow + gotchas.

Workflow

  1. Identify the target — a parameter, endpoint, or form field from orient/recon.
  2. Choose the tool — intruder for parameter fuzzing, ffuzzer for keyword replacement, paramhunter to map params to vulnerability classes.
  3. Configure — payload set, insertion points, processors, concurrency, rate limiting.
  4. Run — monitor results, grep for interesting responses.
  5. Triage — flag interesting hits, send to repeater for confirmation.

Rules

  • Authorised targets only. Stay in scope.
  • Start small — low concurrency, small wordlist. Scale up once the target handles it.
  • paramhunter tells you which parameters are likely vulnerable to which class — use it to prioritize.
  • Re-encode payloads through the insertion point's encoding chain.
  • Evidence over assertion — a fuzzing hit is not a finding until confirmed in repeater.