feroxbuster.md (16603B)
1 --- 2 title: "feroxbuster" 3 description: "feroxbuster recursive content discovery — recursion by default, link extraction, response auto-filtering, and rich matchers/filters." 4 category: enumeration 5 tags: [enumeration, web, brute-force, recursion] 6 tools: [feroxbuster] 7 difficulty: beginner 8 updated: "2026-09-15" 9 --- 10 11 # feroxbuster 12 13 > **feroxbuster** — Fast, simple, recursive content-discovery tool written in Rust (v2.11.x). Author: Ben "epi" Risher (`@epi052`). 14 > Key differentiators over `gobuster`/`dirb`: **recursion is on by default**, it **extracts links** from response bodies (HTML/JS/robots.txt) and scans them, auto-filters obvious wildcard/404 responses, and offers an **interactive scan-management menu** while running. 15 16 ## Installation 17 18 ```bash 19 # Kali / Debian / Ubuntu (repo package) 20 sudo apt install feroxbuster 21 22 # Cargo (Rust toolchain, always latest) 23 cargo install feroxbuster 24 25 # Homebrew (macOS / Linuxbrew) 26 brew install feroxbuster 27 28 # Static binary install script (no root needed, drops ./feroxbuster) 29 curl -sL https://raw.githubusercontent.com/epi052/feroxbuster/main/install-nix.sh | bash 30 31 # Prebuilt release binary (Linux x86_64) 32 curl -sL https://github.com/epi052/feroxbuster/releases/latest/download/x86_64-linux-feroxbuster.tar.gz \ 33 | tar -xz && sudo mv feroxbuster /usr/local/bin/ 34 35 # Docker 36 docker run --init -it ghcr.io/epi052/feroxbuster:latest \ 37 -u http://target.com -w /wordlists/common.txt 38 ``` 39 40 ```bash 41 feroxbuster -h # concise help 42 feroxbuster --help # full help with every flag and default 43 feroxbuster -V # version 44 ``` 45 46 ## Quick Start 47 48 ```bash 49 # The one command you'll run 90% of the time — recursion is automatic 50 feroxbuster -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt 51 52 # With extensions and a saved log 53 feroxbuster -u http://10.10.10.100 \ 54 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ 55 -x php,html,txt -o ferox.txt 56 ``` 57 58 ## Core Flags 59 60 | Flag | Short | Description | 61 |------|-------|-------------| 62 | `--url <url>` | `-u` | Target URL. **Repeatable** — pass `-u` multiple times to scan several targets | 63 | `--wordlist <path>` | `-w` | Wordlist path (default: `/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt`) | 64 | `--threads <int>` | `-t` | Total number of concurrent threads (default: `50`) | 65 | `--depth <int>` | `-d` | Maximum recursion depth; `0` means recurse infinitely (default: `4`) | 66 | `--extensions <exts>` | `-x` | Extensions to append, comma-separated (`php,html,txt`). Use `-x tar.gz` etc. for multi-part | 67 | `--methods <methods>` | `-m` | HTTP methods to try, comma-separated (default: `GET`) | 68 | `--data <data>` | | Request body to send (e.g. for `POST`); accepts `@file` to read from a file | 69 | `--stdin` | | Read the target URL(s) from STDIN instead of `-u` | 70 | `--output <file>` | `-o` | Write results to a file (plain text, or JSON with `--json`) | 71 | `--json` | | Emit newline-delimited JSON (great for piping / jq) | 72 | `--silent` | | Machine-readable output only — URLs, no banner or progress (ideal for piping) | 73 | `--quiet` | `-q` | Suppress the progress bars and banner but keep status lines | 74 | `--verbosity` | `-v` | Increase log verbosity (`-v`, `-vv`, `-vvvv`) | 75 | `--no-recursion` | `-n` | Disable recursion entirely (behave like gobuster `dir`) | 76 | `--add-slash` | `-f` | Append `/` to each word (find directories that only answer with a trailing slash) | 77 | `--resume-from <state>` | | Resume a previous scan from its `ferox-<ts>.state` file | 78 79 ## HTTP / Request Flags 80 81 | Flag | Short | Description | 82 |------|-------|-------------| 83 | `--headers <header>` | `-H` | Custom header, repeatable (`-H 'Authorization: Bearer …' -H 'X-Api: 1'`) | 84 | `--cookies <cookie>` | `-b` | Cookie(s) to send, repeatable (`-b 'PHPSESSID=abc'`) | 85 | `--query <param>` | `-Q` | Query-string parameter, repeatable (`-Q 'debug=1'`) | 86 | `--user-agent <string>` | `-a` | Set the User-Agent (default: `feroxbuster/<version>`) | 87 | `--random-agent` | `-A` | Pick a random User-Agent per scan from a built-in list | 88 | `--redirects` | `-r` | Follow 3xx redirects (off by default — 301/302 are reported, not followed) | 89 | `--insecure` | `-k` | Disable TLS certificate validation | 90 | `--proxy <url>` | `-p` | Proxy all traffic (`http://127.0.0.1:8080`, `socks5://127.0.0.1:1080`) | 91 | `--replay-proxy <url>` | `-P` | Send **only matched** responses to a second proxy (e.g. Burp) to cut noise | 92 | `--replay-codes <codes>` | `-R` | Status codes that get sent to the replay proxy (default: your match codes) | 93 | `--burp` | | Shortcut for `--proxy http://127.0.0.1:8080 --insecure` | 94 | `--burp-replay` | | Shortcut for `--replay-proxy http://127.0.0.1:8080 --insecure` | 95 | `--server-certs <pem>` | | Trust a custom CA / self-signed server cert (repeatable) | 96 | `--client-cert <pem>` | | Client certificate for mTLS | 97 | `--client-key <pem>` | | Client private key for mTLS | 98 | `--timeout <secs>` | `-T` | Per-request timeout in seconds (default: `7`) | 99 100 ## Status Codes, Matchers & Filters 101 102 feroxbuster's real power is filtering. By default it reports status codes `200-299, 301, 302, 307, 308, 401, 403, 405` and auto-filters wildcard responses. Tune with: 103 104 | Flag | Short | Description | 105 |------|-------|-------------| 106 | `--status-codes <codes>` | `-s` | Whitelist: only report these status codes (space/comma separated) | 107 | `--filter-status <codes>` | `-C` | Blacklist: hide these status codes (e.g. `-C 404,403`) | 108 | `--filter-size <bytes>` | `-S` | Hide responses of exactly these byte sizes (repeatable) | 109 | `--filter-words <count>` | `-W` | Hide responses with this many words | 110 | `--filter-lines <count>` | `-N` | Hide responses with this many lines | 111 | `--filter-regex <regex>` | `-X` | Hide responses whose body matches this regex | 112 | `--filter-similar-to <url>` | | Hide responses fuzzy-similar (ssdeep) to a known page — kills soft-404s | 113 | `--dont-filter` | | Turn OFF wildcard/auto filtering (report literally everything) | 114 115 > **Workflow — kill false positives fast:** Run once, spot a repeating bogus size/word/line count in the output, then re-run adding `-S <size>` / `-W <words>` / `-N <lines>`. For soft-404 pages that vary in size, `--filter-similar-to http://target/definitely-404-page` is the sharpest tool. 116 117 ## Recursion Control 118 119 | Flag | Description | 120 |------|-------------| 121 | `-n`, `--no-recursion` | Disable recursion completely | 122 | `-d`, `--depth <int>` | Cap recursion depth (`0` = unlimited; default `4`) | 123 | `--force-recursion` | Recurse into every discovered URL even without a trailing slash / not obviously a directory | 124 | `-L`, `--scan-limit <int>` | Max number of directory scans running concurrently (throttles a recursion explosion) | 125 | `-I`, `--dont-scan <regex>` | Skip URLs matching this regex, repeatable (e.g. `-I 'logout' -I '\.js$'`) | 126 127 ```bash 128 # Deep but controlled: unlimited depth, but only 3 directories scanned at once 129 feroxbuster -u http://target -w wordlist.txt -d 0 -L 3 130 131 # Recurse everywhere, but never into logout or static asset paths 132 feroxbuster -u http://target -w wordlist.txt --force-recursion -I 'logout' -I '\.(js|css|png|jpg)$' 133 ``` 134 135 ## Link Extraction & Collection 136 137 feroxbuster parses response bodies and pulls out more targets automatically: 138 139 | Flag | Short | Description | 140 |------|-------|-------------| 141 | `--extract-links` | `-e` | Parse HTML/JS/`robots.txt` for links and scan them (on by default in recent builds; flag forces it) | 142 | `--dont-extract-links` | | Turn link extraction off | 143 | `--scan-dir-listings` | | Also brute-force inside auto-indexed (`Index of /`) directory listings | 144 | `--collect-extensions` | | Learn extensions seen in responses and add them to the scan on the fly | 145 | `--collect-backups` | | On each found page, also request backup variants (`.bak`, `~`, `.old`, …) | 146 | `--collect-words` | | Harvest words from responses and add them to the wordlist mid-scan | 147 148 ```bash 149 # "Just find everything" mode — collect extensions, backups, and words as it goes 150 feroxbuster -u http://target -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ 151 --collect-extensions --collect-backups --collect-words 152 ``` 153 154 ## Performance & Stealth 155 156 | Flag | Short | Description | 157 |------|-------|-------------| 158 | `--threads <int>` | `-t` | Concurrent threads (default `50`) | 159 | `--rate-limit <int>` | | Cap requests **per second** per directory scan | 160 | `--scan-limit <int>` | `-L` | Concurrent directory scans | 161 | `--time-limit <spec>` | | Stop after a duration (`10m`, `1h`, `30s`) | 162 | `--auto-tune` | | Automatically slow down when the server starts erroring, then speed back up | 163 | `--auto-bail` | | Abort a scan that trips too many errors/timeouts/403s (guards against WAF bans) | 164 | `--smart` | | Preset: `--auto-tune --collect-words --collect-backups --extract-links` | 165 | `--thorough` | | Preset: everything `--smart` does plus `--collect-extensions --scan-dir-listings` | 166 167 ```bash 168 # Gentle scan against a rate-limited / WAF'd target 169 feroxbuster -u http://target -w wordlist.txt --rate-limit 20 --auto-tune --auto-bail 170 171 # Aggressive but self-throttling one-liner 172 feroxbuster -u http://target -w wordlist.txt --thorough --auto-tune 173 ``` 174 175 ## Interactive Scan Menu 176 177 While a scan is running, press **`Enter`** to open the interactive menu. From there you can: 178 179 - List all active recursive scans with their IDs. 180 - **Cancel** a runaway scan (e.g. a huge auto-indexed directory) without killing the whole run: type the scan number(s) and confirm. 181 - Cancelled scans are pruned so the rest of the run continues. 182 183 This is the main reason to prefer feroxbuster on messy targets — you prune noisy recursion live instead of restarting. 184 185 ## Practical Examples 186 187 ```bash 188 # Basic recursive scan with extensions 189 feroxbuster -u http://10.10.10.100 \ 190 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ 191 -x php,html,txt 192 193 # Authenticated scan (session cookie + bearer token) 194 feroxbuster -u http://10.10.10.100 \ 195 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ 196 -b 'PHPSESSID=abc123def456' -H 'Authorization: Bearer eyJhbGciOi...' 197 198 # Over HTTPS with a bad cert, following redirects 199 feroxbuster -u https://10.10.10.100 -w wordlist.txt -k -r 200 201 # Proxy everything through Burp 202 feroxbuster -u http://10.10.10.100 -w wordlist.txt --burp 203 204 # Scan fast, but replay only interesting hits to Burp 205 feroxbuster -u http://10.10.10.100 -w wordlist.txt -t 100 \ 206 --replay-proxy http://127.0.0.1:8080 --replay-codes 200,301,302 207 208 # Filter out a soft-404 baseline (page is 200 but always ~1274 bytes / 96 words) 209 feroxbuster -u http://10.10.10.100 -w wordlist.txt -S 1274 -W 96 210 211 # Only show 200s and 301s 212 feroxbuster -u http://10.10.10.100 -w wordlist.txt -s 200,301 213 214 # Hide 403/404 noise 215 feroxbuster -u http://10.10.10.100 -w wordlist.txt -C 403,404 216 217 # POST-based content discovery 218 feroxbuster -u http://10.10.10.100 -w wordlist.txt -m POST --data 'action=FUZZ' 219 220 # Multiple targets in one run 221 feroxbuster -u http://10.10.10.100 -u http://10.10.10.101 -w wordlist.txt 222 223 # Pipe a list of live hosts from httpx into a parallel scan 224 cat live_hosts.txt | feroxbuster --stdin -w wordlist.txt --silent 225 226 # Save both a human log and machine-readable JSON 227 feroxbuster -u http://10.10.10.100 -w wordlist.txt -o ferox.txt 228 feroxbuster -u http://10.10.10.100 -w wordlist.txt --json -o ferox.json 229 ``` 230 231 ## FUZZ Keyword 232 233 feroxbuster substitutes the `FUZZ` keyword anywhere in the URL, headers, cookies, query, or body — combine with multiple wordlists for positional fuzzing: 234 235 ```bash 236 # Fuzz a path segment 237 feroxbuster -u http://10.10.10.100/FUZZ/admin -w wordlist.txt 238 239 # Fuzz a query-parameter value 240 feroxbuster -u 'http://10.10.10.100/item?id=FUZZ' -w /usr/share/seclists/Fuzzing/4-digits-0000-9999.txt 241 242 # Fuzz a header value 243 feroxbuster -u http://10.10.10.100 -H 'X-Forwarded-For: FUZZ' -w ips.txt 244 ``` 245 246 ## Resume & State Files 247 248 Every scan writes a `ferox-<timestamp>.state` file on interruption (`Ctrl-C`) so nothing is lost: 249 250 ```bash 251 # Ctrl-C mid-scan writes ferox-1694781234.state, then: 252 feroxbuster --resume-from ferox-1694781234.state 253 ``` 254 255 ## Config File (`ferox-config.toml`) 256 257 Persistent defaults live in `ferox-config.toml`, searched in the current directory, then `~/.config/feroxbuster/`, then `/etc/feroxbuster/`. Generate a documented template: 258 259 ```bash 260 # The repo ships a fully-commented template 261 curl -sL https://raw.githubusercontent.com/epi052/feroxbuster/main/ferox-config.toml.example \ 262 -o ~/.config/feroxbuster/ferox-config.toml 263 ``` 264 265 ```toml 266 # ~/.config/feroxbuster/ferox-config.toml 267 wordlist = "/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt" 268 threads = 50 269 depth = 3 270 extensions = ["php", "html", "txt", "bak"] 271 auto_tune = true 272 # status codes to hide by default 273 filter_status = [404] 274 ``` 275 276 ## Recommended Wordlists 277 278 | Purpose | Path | 279 |---------|------| 280 | feroxbuster default | `/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt` | 281 | Directories (large) | `/usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt` | 282 | Files | `/usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt` | 283 | Common (small/fast) | `/usr/share/seclists/Discovery/Web-Content/common.txt` | 284 | API endpoints | `/usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt` | 285 | Backup/config files | `/usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt` (add `--collect-backups`) | 286 | Kali built-in common | `/usr/share/wordlists/dirb/common.txt` | 287 | Kali built-in big | `/usr/share/wordlists/dirb/big.txt` | 288 289 ## Extension Stacking by Tech Stack 290 291 Match `-x` to the detected technology (or let `--collect-extensions` learn them): 292 293 ```bash 294 # PHP: -x php,phps,php5,phtml,inc,bak 295 # ASP/.NET: -x asp,aspx,ashx,asmx,config 296 # Java: -x jsp,jspx,do,action 297 # Node/JS: -x js,json,ts,map 298 # Python: -x py,pyc,wsgi 299 # Backups: -x bak,old,orig,save,swp,txt,zip,tar.gz (or just --collect-backups) 300 ``` 301 302 ## Quick Reference — Common Workflows 303 304 ### HTB / CTF Initial Enumeration 305 306 ```bash 307 # One recursive pass with extensions, collect as you go, gentle auto-tuning 308 feroxbuster -u http://target.htb \ 309 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ 310 -x php,html,txt -C 404 --collect-extensions --auto-tune -o ferox_initial.txt 311 ``` 312 313 ### Web App Pentest via Burp 314 315 ```bash 316 # Fast scan, but only matched hits land in Burp's proxy history for triage 317 feroxbuster -u https://target.com \ 318 -w /usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt \ 319 -x php,bak,old,conf -k -t 80 \ 320 --replay-proxy http://127.0.0.1:8080 --replay-codes 200,301,302,401 \ 321 -o ferox_pentest.txt 322 ``` 323 324 ### Bug Bounty — many hosts, be polite 325 326 ```bash 327 subfinder -d target.com -silent | httpx -silent \ 328 | feroxbuster --stdin -w wordlist.txt --rate-limit 15 --auto-tune --auto-bail --silent -o ferox_bb.txt 329 ``` 330 331 ## Troubleshooting 332 333 | Problem | Solution | 334 |---------|----------| 335 | Everything returns the same status/size (wildcard) | Auto-filtered by default; if not, add `-S`/`-W`/`-N` or `--filter-similar-to <404-url>` | 336 | Recursion exploding on a huge directory | Press `Enter`, open the menu, cancel that scan; or pre-empt with `-L` and `-I <regex>` | 337 | Flooded with 403s / getting banned | Add `--auto-bail`, lower `--rate-limit`, try `--random-agent` | 338 | Scan too slow | Raise `-t` and drop `--rate-limit`; verify `--auto-tune` isn't throttling on errors | 339 | TLS / self-signed cert errors | Add `-k` (or `--server-certs ca.pem` to trust a specific CA) | 340 | Missing redirected content | Add `-r` to follow 3xx | 341 | Soft-404 pages (200 with "not found" text) | `--filter-similar-to` a known bad URL, or `-X 'not found'` regex filter | 342 | Lost a long scan to Ctrl-C | `--resume-from ferox-<ts>.state` | 343 | Too much noise in Burp | Use `--replay-proxy` + `--replay-codes` instead of `--proxy` | 344 345 ## feroxbuster vs the Alternatives 346 347 | Tool | Language | Key Advantage | 348 |------|----------|---------------| 349 | **feroxbuster** | Rust | Recursion by default, link extraction, live scan-cancel menu, auto-tune/auto-bail | 350 | **ffuf** | Go | Multiple `FUZZ` positions, richest matcher/filter syntax, clusterbomb/pitchfork modes | 351 | **gobuster** | Go | Simple, fast, dedicated `dns`/`vhost`/`s3` modes | 352 | **dirsearch** | Python | Built-in recursion, smart extension substitution | 353 354 ## See Also 355 356 - **[ffuf](/enumeration/ffuf)** — when you need multi-position fuzzing and advanced matchers. 357 - **[gobuster](/enumeration/gobuster)** — when you specifically want DNS/vhost/S3 modes. 358 359 Based on feroxbuster v2.11.x — https://github.com/epi052/feroxbuster