80, 443 - HTTP/S
Last updated
Last updated
General purpose automatic scanners:
List of spidering tools:
Tools:
Dirsearch (python): It doesn't allow auto-signed certificates but allows recursive search.
Gobuster (go): It allows auto-signed certificates, it doesn't have recursive search.
Feroxbuster - Fast, supports recursive search.
wfuzz wfuzz -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt https://domain.com/api/FUZZ
ffuf - Fast: ffuf -c -w /usr/share/wordlists/dirb/big.txt -u http://10.10.10.10/FUZZ
Chamaleon: It uses wapalyzer to detect used technologies and select the wordlists to use.
Note:
Iterate over the results.
Include status code 403 (Forbidden Error) and brutefoce these directories.
Add more file extensions to search for; In gobuster
: -x sh,pl.
Fuzz parameters using injection payloads:
Included in Kali’s wordlists package under /usr/share/wordlists
.
/rockyou.txt
/dirbuster/directory-list-2.3-medium.txt
( 1.9M - 220560 lines )
/dirbuster/directory-list-2.3-small.txt
( 709K - 87664 lines )
/dirb/common.txt
( 36K - 4614 lines )
/dirb/big.txt
( 180K - 20469 lines )