Run your first scan
Learn how to set up your first collection and begin fuzzing in under 5 minutes.
1. Sign-up
If you haven't already, sign-up to Fuzzing-Hero at https://fuzzinghero.com.
New users automatically get 10 scan credits for free.
2. Create a collection
Bring your own OpenAPI docs or Postman collections, or you can create a new collection from scratch.
Create from scratch
- On the Collections page, click New Collection.
- Define a collection name and description.
- Select a visibility option of private or organization. Choosing organization will prompt for you to select an existing organization.
- Click the Create Collection button.
- Your new collection should be available in the Collections list categorized by your visibility selection.
Import OpenAPI docs or Postman collections
On the Collections page, click Import button in the upper-right corner. Select Browse Files or drag and drop your Postman-formatted collections, OpenAPI 3.x, or Swagger/2.0 docs. JSON or YAML formats are accepted.
3. Manage your requests
Navigate to your collection and click on the card to open the requests view.
If you imported your collection you should have a few requests already populated. If you manually created your collection, you will need to add some requests to get started. To do so, click on the + icon next to Requests on the left pane. A new request should be added to your requests list. Click on the request entry that you wish to edit.
Each request needs at minimum the following:
- HTTP Method/Verb (GET, POST, PATCH, DELETE, etc.)
- URI (https://api.fuzzinghero.com/auth/me)
You can add an optional name to identify requests. We also support different HTTP protocols if you know your service only accepts a specific version (e.g., HTTP/1.1, HTTP/2), but the default Auto mode will take care of the guess work.
Query parameters can be managed on the Params tab. Similarly, Headers can be managed on the Headers tab and the request body can be managed on the Body tab.
Once your request has been configured, click the Save button to save your changes. Next hit the Test button to check to see if Fuzzing Hero is able to send the request and get a response from the web service.
A banner will appear to indicate the test status. A 200 status code, or otherwise successful response, will indicate that the request is ready to be fuzzed. If you receive an error message, then you should adjust your request before proceeding. Head over to Troubleshooting for more help.
4. Configure collection settings
-
Click the Settings button to open up collection settings.
-
On the General tab, you can rename the collection, change the description, or adjust the collection's visibility setting.
-
On the Authentication tab, you can configure authentication for your collection. If your application uses authentication, you can configure that by selecting an authentication type, such as Bearer Token, Basic Auth, Cookies, or a Custom Header.
- You can optionally designate a single request in your collection as the "Auth Check Request", which will not be fuzzed and will strictly be used to ensure authentication works throughout the duration of your scan.
-
The Scan Categories tab allows you to customize what kinds of testing any new scans will perform. We recommend testing everything by default.
-
The Scan Settings page allows you to modify some parameters about how the scan is performed or how the results should be presented.
-
Once you've made any changes you'd like to the collection or scan settings, click the Save Changes button.
5. Start scan
From the requests view, click the Start Scan button. This will bring up a health check that will test each of your requests to make sure that the target application can be reached by Fuzzing Hero and that all of your requests are properly configured.
We recommend making sure that the health check passes before continuing to the next step. If the health check identifies any problems, Fuzzing Hero will warn you about any error-related statuses or networking problems. These issues will need to be resolved prior to starting a scan. Scans can be kicked off in this state, but are much less likely to complete or have useful results.
Fuzzing Hero asks that you authorize each scan by attesting that you have permission to perform security testing on the target application. For questions about what is and isn't allowed, please refer to our Terms of Service.
Once you've authorized the scan by clicking the checkbox, click the Start Fuzzing button.
6. Running the scan
Fuzzing Hero will move the scan state from pending to active once it's started working on the scan. You will be able to track it's progress while it's active and see how many requests it has sent and how long it's been running.
If you decide to stop your scan while it's running, click the Stop Scan button. The scan will be moved to a stopped state and you will no longer be able to view its progress.
7. Reviewing scan results
After a scan has completed, you will be able to dig into the scan results.
Fuzzing Hero gives you a high level overview of how many scan issues and observations were detected, the duration of the scan, and how many requests were sent.
You can click through any scan issues and observations to learn more about what was found and to view evidence.
Fuzzing Hero also provides a tab to show you Response Partitions, which is our way of helping you evaluate the quality of the fuzzing and it can lead to some valuable insights. For more information, check out Response Partitions.
Learn about what parameters the engine discovered by inspecting the Discovered Parameters tab. This will give you an understanding into what was fuzzed in each of the collection's HTTP requests.
We also make HAR files available for download via the Export Report button. You have access to the HTTP requests and responses that Fuzzing Hero saw while scanning the target API.
8. Next steps
We hope that you will find value in using Fuzzing Hero to test your APIs. Leverage our platform to help dig into your applications and find bugs before they become a problem.
We recommend checking out Directives and Validators and Organizations to learn how to bring in more customization and collaboration to your work.