I am working on Linux. What I want to do is to fuzz a web application by afl++. My goal is not to find the risk of XSS/CSRF... (I think I can use ZAP or Burp to handle it.)