Skip to main content

Compare Scan Variants

When Fuzzing Hero discovers a security issue or anomalous behavior, it compiles one or more fuzzed transactions that prove the vulnerability exists. These proofs are called Variants.

To easily diagnose and patch the bug, Fuzzing Hero provides an interactive diffing inspector to compare these fuzzed variants side-by-side with the original, expected transaction (the Baseline).

Comparing a Variant with the Baseline​

  1. From your scan results page, select the issue you wish to investigate from the Issues Found list.
  2. In the right-hand Issue Inspector pane, locate the tab strip below the issue description.
  3. Click the Baseline tab to view the original HTTP request and response that succeeded under normal conditions.
  4. Click on any of the Variant X tabs (e.g., Variant 1, Variant 2, or OOB for out-of-band interactions) to view the malformed transaction sent by the fuzzing engine.
  5. In the Request section, click Compare Request w/ Baseline to view the exact parameter changes injected by the scanner.
  6. In the Response section, click Compare Response w/ Baseline to view how the application's response differed from the baseline.

Reading the Diff Viewer​

Fuzzing Hero's diff viewer highlights lines changed during fuzzing:

  • Green lines (prefixed with +) indicate data added or modified in the fuzzed request or response.
  • Red lines (prefixed with -) indicate data removed from the baseline request or response.
  • Grey lines (prefixed with two spaces) indicate matching, unchanged data.

Inspecting Timings​

Timing anomalies are a common sign of database injection (such as SQL time-based blind attacks) or denial of service issues.

When viewing a fuzzed variant tab:

  • The header displays the response latency of that specific transaction (e.g. Time: 5005ms).
  • If available, it shows the baseline latency alongside it (e.g. (Base: 42ms)) to help you immediately identify timing differences.