Gobuster: Fast Brute-Force Directory, DNS, and VHost Enumeration
Gobuster is a command-line tool used to brute-force URIs (directories and files), DNS subdomains, and virtual hostnames on target web servers. Written in Go, it’s known for its speed and efficiency in reconnaissance phases of penetration testing and bug bounty hunting. It’s an excellent tool for discovering hidden web content or subdomains that might not be linked from public pages.
Prerequisites: Wordlists
Gobuster heavily relies on wordlists for its brute-forcing capabilities. A popular collection of wordlists is SecLists.
# Download SecLists
git clone https://github.com/danielmiessler/SecLists.git /opt/SecListsNote on Gobuster Versions: Some advanced features or flag behaviors might differ slightly between gobuster versions, especially if you’re using a version packaged specifically for a distribution like Kali Linux versus a version installed directly from source or a generic package manager. Always refer to your installed version’s help (gobuster --help) if you encounter unexpected behavior.
1. Directory and File Enumeration (dir mode)
This mode is used to discover hidden directories and files on a web server.
# Basic directory enumeration
gobuster dir -v -w /opt/SecLists/Discovery/Web-Content/common.txt -u http://<target.com>
# Example: More verbose output, useful for seeing all attempts (found and missed)
gobuster dir -e -v -w /opt/SecLists/Discovery/Web-Content/common.txt -u http://<target.com>Flags Explained:
dir: Specifies the mode for directory/file brute-forcing.-v: Verbose output, which shows both found and missed attempts.-w <wordlist_path>: Specifies the path to the wordlist containing common directory and file names.-u <target_url>: The target URL (e.g.,http://example.com).-e: Expanded mode, prints the full URLs of found entries.-x <extensions>: Appends file extensions (e.g.,-x php,txt,html).
Example: File Enumeration with Extensions
gobuster dir -x php,html -w /opt/SecLists/Discovery/Web-Content/common.txt -u http://<target.com>2. DNS Subdomain Enumeration (dns mode)
This mode is used to discover subdomains for a target domain.
gobuster dns -w /opt/SecLists/Discovery/DNS/subdomains-top1million-5000.txt -d <target.com>Flags Explained:
dns: Specifies the mode for DNS subdomain brute-forcing.-w <wordlist_path>: Specifies the wordlist containing common subdomain names.-d <target_domain>: The target domain (e.g.,example.com).
3. VHost Enumeration (vhost mode)
This mode is used to discover virtual hosts on a web server by brute-forcing Host headers.
gobuster vhost -w /opt/SecLists/Discovery/DNS/subdomains-top1million-5000.txt -u http://<target.com> --append-domainFlags Explained:
vhost: Specifies the mode for virtual host brute-forcing.-w <wordlist_path>: Specifies the wordlist containing potential virtual hostnames.-u <target_url>: The target URL to send requests to.--append-domain: Appends the target domain to the wordlist entries (e.g.,wwwfrom wordlist becomeswww.<target.com>).
Disclaimer: Gobuster is a reconnaissance tool. Its use should be restricted to legal and ethical purposes, such as authorized penetration testing, bug bounty hunting on explicitly allowed scopes, or security research on systems you own or have explicit permission to test. Unauthorized scanning and enumeration of networks are illegal and unethical.