daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

gobuster.md (26545B)


      1 ---
      2 title: "Gobuster"
      3 description: "Gobuster dir, dns, vhost and s3 brute-forcing modes with wordlist and status-code options."
      4 category: enumeration
      5 tags: [enumeration, web, brute-force]
      6 tools: [Gobuster]
      7 difficulty: beginner
      8 updated: "2026-08-09"
      9 source: "vault:Tools/gobuster.md"
     10 ---
     11 
     12 # Gobuster
     13 
     14 > **Gobuster** — Fast brute-force enumeration tool written in Go (v3.8.2, Sep 2025). Authors: OJ Reeves (`@TheColonial`) & Christian Mehlmauer (`@firefart`).
     15 > Capabilities: directory/file, DNS subdomain, virtual host, S3 bucket, GCS bucket, TFTP, and generic fuzzing enumeration.
     16 
     17 ## Installation
     18 
     19 ```bash
     20 # Kali Linux (pre-installed in default metapackage)
     21 sudo apt install gobuster
     22 
     23 # Go install (requires Go 1.24+)
     24 go install github.com/OJ/gobuster/v3@latest
     25 
     26 # Build from source
     27 git clone https://github.com/OJ/gobuster.git
     28 cd gobuster
     29 go mod tidy
     30 go build
     31 
     32 # Docker
     33 docker pull ghcr.io/oj/gobuster:latest
     34 docker run --rm -it ghcr.io/oj/gobuster:latest dir -u https://target.com -w /usr/share/wordlists/dirb/common.txt
     35 ```
     36 
     37 ## Modes Overview
     38 
     39 | Mode | Command | Purpose |
     40 |------|---------|---------|
     41 | `dir` | `gobuster dir` | Directory & file brute-forcing on web servers |
     42 | `dns` | `gobuster dns` | DNS subdomain enumeration |
     43 | `vhost` | `gobuster vhost` | Virtual host discovery via `Host` header manipulation |
     44 | `fuzz` | `gobuster fuzz` | Generic fuzzing — replaces `FUZZ` keyword in URL, headers, and request body |
     45 | `s3` | `gobuster s3` | AWS S3 bucket enumeration |
     46 | `gcs` | `gobuster gcs` | Google Cloud Storage bucket enumeration |
     47 | `tftp` | `gobuster tftp` | TFTP file enumeration |
     48 
     49 ```bash
     50 # Getting help
     51 gobuster -h                  # General help
     52 gobuster help dir            # Help for a specific mode
     53 gobuster dir --help          # Alternative help syntax
     54 ```
     55 
     56 ## Global Flags (Apply to All Modes)
     57 
     58 | Flag | Short | Description |
     59 |------|-------|-------------|
     60 | `--wordlist <path>` | `-w` | Path to the wordlist (set to `-` to read from STDIN) |
     61 | `--threads <int>` | `-t` | Number of concurrent threads (default: `10`) |
     62 | `--output <file>` | `-o` | Write results to a file |
     63 | `--delay <duration>` | | Delay between requests per thread (e.g. `500ms`, `1s`, `1500ms`) |
     64 | `--pattern <file>` | `-p` | File containing replacement patterns using `{GOBUSTER}` placeholder |
     65 | `--wordlist-offset <int>` | | Resume from a given position in the wordlist |
     66 | `--debug` | | Enable debug output (replaces the old `--verbose` flag in v3.7+) |
     67 | `--quiet` | `-q` | Suppress banner and noise |
     68 | `--no-progress` | `-z` | Don't display progress indicator |
     69 | `--no-error` | | Suppress error messages |
     70 | `--no-color` | | Disable colour output |
     71 
     72 > **Note — v3.7+ CLI changes:** From v3.7 onwards, Gobuster switched to a new CLI library. The `--verbose` flag was replaced by `--debug`. Some short flags were also reassigned. Always check `gobuster <mode> --help` on your installed version.
     73 
     74 ## 1. Directory & File Enumeration (`dir`)
     75 
     76 The most commonly used mode. Brute-forces URIs (directories and files) on web servers.
     77 
     78 ### All `dir` Mode Flags
     79 
     80 | Flag | Short | Description |
     81 |------|-------|-------------|
     82 | `--url <url>` | `-u` | **Required.** Target URL |
     83 | `--extensions <exts>` | `-x` | File extensions to search for (comma-separated, e.g. `php,html,txt`) |
     84 | `--extensions-file <file>` | `-X` | Read extensions from a file |
     85 | `--status-codes <codes>` | `-s` | Positive status codes to include. Supports ranges (e.g. `200,300-400,404`) |
     86 | `--status-codes-blacklist <codes>` | `-b` | Negative status codes to exclude. Supports ranges. (default: `404`) |
     87 | `--exclude-length <lengths>` | | Exclude responses by content length. Supports comma-separated values and ranges (e.g. `0,203-206,1234`) |
     88 | `--method <method>` | `-m` | HTTP method to use (default: `GET`) |
     89 | `--cookies <string>` | `-c` | Cookies to include in requests |
     90 | `--headers <header>` | `-H` | Custom HTTP headers (repeatable: `-H 'Header1: val1' -H 'Header2: val2'`) |
     91 | `--useragent <string>` | `-a` | Set the User-Agent string |
     92 | `--random-agent` | | Use a random User-Agent string per request |
     93 | `--username <user>` | `-U` | Username for HTTP Basic Auth |
     94 | `--password <pass>` | `-P` | Password for HTTP Basic Auth |
     95 | `--proxy <url>` | | Proxy to use (`http(s)://host:port` or `socks5://host:port`) |
     96 | `--follow-redirect` | `-r` | Follow HTTP redirects |
     97 | `--no-tls-validation` | `-k` | Skip TLS certificate verification |
     98 | `--timeout <duration>` | | HTTP request timeout (default: `10s`) |
     99 | `--add-slash` | `-f` | Append `/` to each request |
    100 | `--expanded` | `-e` | Print full URLs in output |
    101 | `--no-status` | `-n` | Don't print status codes |
    102 | `--hide-length` | | Hide the body length in output |
    103 | `--discover-backup` | `-d` | On finding a file, also search for backup file variations |
    104 | `--no-canonicalize-headers` | | Send HTTP header names as-is (don't canonicalize) |
    105 | `--retry` | | Retry on request timeout |
    106 | `--retry-attempts <int>` | | Number of retries (default: `3`) |
    107 | `--force` | | Continue execution even if precheck errors occur (v3.8+) |
    108 | `--client-cert-p12 <file>` | | P12 file for mTLS client certificates |
    109 | `--client-cert-p12-password <pass>` | | Password for the P12 file |
    110 | `--client-cert-pem <file>` | | PEM public key for mTLS |
    111 | `--client-cert-pem-key <file>` | | PEM private key for mTLS (must have no password) |
    112 
    113 ### Practical Examples
    114 
    115 ```bash
    116 # Basic directory enumeration
    117 gobuster dir -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
    118 
    119 # Search for specific file extensions
    120 gobuster dir -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt \
    121   -x php,html,txt,bak,old,conf,xml,json
    122 
    123 # Extensions loaded from a file
    124 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \
    125   -X /home/kali/extensions.txt
    126 
    127 # With authentication cookie (e.g. post-login enumeration)
    128 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/big.txt \
    129   -c "PHPSESSID=abc123def456" -x php
    130 
    131 # HTTP Basic Auth
    132 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \
    133   -U admin -P password123
    134 
    135 # Custom header (e.g. JWT / Bearer token)
    136 gobuster dir -u http://10.10.10.100/api -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt \
    137   -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIs..."
    138 
    139 # Follow redirects and skip TLS errors
    140 gobuster dir -u https://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -r -k
    141 
    142 # Proxy through Burp Suite
    143 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \
    144   --proxy http://127.0.0.1:8080
    145 
    146 # SOCKS5 proxy (e.g. through ligolo-ng or SSH tunnel)
    147 gobuster dir -u http://172.16.1.10 -w /usr/share/wordlists/dirb/common.txt \
    148   --proxy socks5://127.0.0.1:1080
    149 
    150 # Filter false positives by excluding response lengths
    151 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \
    152   --exclude-length 0,4523
    153 
    154 # Only show specific status codes (supports ranges)
    155 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \
    156   -s 200,301,302
    157 
    158 # Blacklist status codes
    159 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \
    160   -b 403,404
    161 
    162 # Random user agent to evade basic fingerprinting
    163 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \
    164   --random-agent
    165 
    166 # High threads with rate limiting
    167 gobuster dir -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt \
    168   -t 50 --delay 100ms
    169 
    170 # Auto-discover backup files alongside regular enumeration
    171 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -d
    172 
    173 # POST method enumeration
    174 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -m POST
    175 
    176 # Resume a scan from a specific wordlist offset
    177 gobuster dir -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt \
    178   --wordlist-offset 5000
    179 
    180 # Force continue even if precheck fails (v3.8+)
    181 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt --force
    182 
    183 # Read wordlist from STDIN (piping)
    184 cat custom_wordlist.txt | gobuster dir -u http://10.10.10.100 -w -
    185 
    186 # mTLS client certificate authentication
    187 gobuster dir -u https://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \
    188   --client-cert-pem client.pem --client-cert-pem-key client-key.pem
    189 
    190 # Save output to file
    191 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -o results.txt
    192 ```
    193 
    194 ## 2. DNS Subdomain Enumeration (`dns`)
    195 
    196 Discovers subdomains via DNS resolution. Requires the target domain to be resolvable.
    197 
    198 ### All `dns` Mode Flags
    199 
    200 | Flag | Short | Description |
    201 |------|-------|-------------|
    202 | `--domain <domain>` | `-d` | **Required.** Target domain |
    203 | `--resolver <server>` | `-r` | Custom DNS resolver (e.g. `8.8.8.8` or `8.8.8.8:53`) |
    204 | `--show-ips` | `-i` | Show resolved IP addresses in results |
    205 | `--show-cname` / `--check-cname` | `-c` | Show CNAME records (cannot be combined with `-i`). Renamed to `--check-cname` in v3.7+ |
    206 | `--timeout <duration>` | | DNS resolver timeout (default: `1s`) |
    207 | `--wildcard` | | Force continued operation when a wildcard DNS record is detected |
    208 | `--no-fqdn` | | Don't automatically append a trailing dot — disables system search domains (can speed up scans, v3.6+) |
    209 
    210 ### Practical Examples
    211 
    212 ```bash
    213 # Basic subdomain enumeration
    214 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
    215 
    216 # Show resolved IP addresses alongside subdomains
    217 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt -i
    218 
    219 # Use a custom DNS resolver (bypass internal/split-horizon DNS)
    220 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \
    221   -r 1.1.1.1
    222 
    223 # Show CNAME records (useful for subdomain takeover identification)
    224 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -c
    225 
    226 # Force operation on wildcard domains
    227 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt --wildcard
    228 
    229 # High thread count for large wordlists
    230 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -t 50
    231 
    232 # Disable FQDN trailing dot (skip system search domains for speed)
    233 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt \
    234   --no-fqdn -t 50
    235 
    236 # Save results
    237 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \
    238   -i -o subdomains.txt
    239 ```
    240 
    241 > **Tip — DNS enumeration pre-requisite:** Ensure the target domain actually resolves. If behind a firewall or using split-horizon DNS, you may need to specify a resolver (`-r`) that has visibility into the target's DNS zone.
    242 
    243 ## 3. Virtual Host Discovery (`vhost`)
    244 
    245 Sends HTTP requests with different `Host:` headers to find virtual hosts on a web server. Unlike DNS mode, this does **not** require DNS resolution — it works directly against the server IP.
    246 
    247 ### All `vhost` Mode Flags
    248 
    249 | Flag | Short | Description |
    250 |------|-------|-------------|
    251 | `--url <url>` | `-u` | **Required.** Target URL (typically use the IP address) |
    252 | `--domain <domain>` | | Domain to append to wordlist entries |
    253 | `--append-domain` | | Append the main domain from the URL to each wordlist word |
    254 | `--exclude-length <lengths>` | | Exclude responses by content length (comma-separated, supports ranges) |
    255 | `--method <method>` | `-m` | HTTP method (default: `GET`) |
    256 | `--cookies <string>` | `-c` | Cookies for requests |
    257 | `--headers <header>` | `-H` | Custom headers (repeatable) |
    258 | `--follow-redirect` | `-r` | Follow redirects |
    259 | `--no-tls-validation` | `-k` | Skip TLS verification |
    260 | `--proxy <url>` | | Proxy to use |
    261 | `--random-agent` | | Use random User-Agent |
    262 | `--useragent <string>` | `-a` | Set User-Agent |
    263 | `--username <user>` | `-U` | HTTP Basic Auth username |
    264 | `--password <pass>` | `-P` | HTTP Basic Auth password |
    265 | `--timeout <duration>` | | HTTP timeout (default: `10s`) |
    266 | `--retry` | | Retry on timeout |
    267 | `--retry-attempts <int>` | | Number of retries (default: `3`) |
    268 | `--no-canonicalize-headers` | | Don't canonicalize header names |
    269 | `--client-cert-*` | | mTLS client certificate options (same as dir mode) |
    270 
    271 ### Practical Examples
    272 
    273 ```bash
    274 # Basic vhost discovery — with --append-domain to build FQDN Host headers
    275 gobuster vhost -u http://10.10.10.100 \
    276   -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \
    277   --domain target.htb --append-domain
    278 
    279 # Filter false positives by excluding a known baseline response length
    280 gobuster vhost -u http://10.10.10.100 \
    281   -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \
    282   --domain target.htb --append-domain --exclude-length 301
    283 
    284 # Over HTTPS with TLS skip
    285 gobuster vhost -u https://10.10.10.100 \
    286   -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \
    287   --domain target.htb --append-domain -k
    288 
    289 # High thread count
    290 gobuster vhost -u http://10.10.10.100 \
    291   -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt \
    292   --domain target.htb --append-domain -t 50
    293 ```
    294 
    295 > **Important — VHost vs DNS mode:**
    296 > - Use **DNS mode** to discover subdomains via actual DNS resolution.
    297 > - Use **VHost mode** when the server hosts multiple sites on the same IP and you need to discover them by manipulating the `Host` header.
    298 > - **VHost is the go-to for HTB/CTF targets** where you've added the base domain to `/etc/hosts` and want to find additional virtual hosts.
    299 > - From v3.7+, Gobuster warns you if `--append-domain` might have been forgotten.
    300 
    301 ## 4. Fuzz Mode (`fuzz`)
    302 
    303 The most flexible mode. Replaces the keyword `FUZZ` in the URL, headers, and request body with wordlist entries.
    304 
    305 ### Key `fuzz` Mode Flags
    306 
    307 Fuzz mode shares most HTTP flags with `dir` mode, plus:
    308 
    309 | Feature | Flag | Description |
    310 |---------|------|-------------|
    311 | URL fuzzing | `-u` | Include `FUZZ` in the URL |
    312 | Header fuzzing | `-H` | Include `FUZZ` in header values |
    313 | Body fuzzing | `-d` | Include `FUZZ` in POST body data (v3.3+) |
    314 | Host header fuzzing | `-H "Host: FUZZ.domain"` | Supported natively in v3.7+ |
    315 | Exclude lengths | `--exclude-length` | Filter false positives |
    316 | Blacklist codes | `-b` | Exclude status codes |
    317 
    318 ### Practical Examples
    319 
    320 ```bash
    321 # Fuzz URL paths
    322 gobuster fuzz -u http://10.10.10.100/FUZZ -w /usr/share/wordlists/dirb/common.txt
    323 
    324 # Fuzz API endpoints
    325 gobuster fuzz -u http://10.10.10.100/api/v1/FUZZ \
    326   -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt
    327 
    328 # Fuzz URL parameters (parameter name discovery)
    329 gobuster fuzz -u "http://10.10.10.100/page?FUZZ=test" \
    330   -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt
    331 
    332 # Fuzz parameter values
    333 gobuster fuzz -u "http://10.10.10.100/page?id=FUZZ" \
    334   -w /usr/share/seclists/Fuzzing/4-digits-0000-9999.txt
    335 
    336 # Fuzz the Host header (alternative to vhost mode, more control)
    337 gobuster fuzz -u http://10.10.10.100 \
    338   -H "Host: FUZZ.target.htb" \
    339   -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \
    340   --exclude-length 1234
    341 
    342 # Fuzz POST body data (v3.3+)
    343 gobuster fuzz -u http://10.10.10.100/login \
    344   -d "username=admin&password=FUZZ" \
    345   -w /usr/share/seclists/Passwords/Common-Credentials/10k-most-common.txt
    346 
    347 # Fuzz custom headers
    348 gobuster fuzz -u http://10.10.10.100 \
    349   -H "X-Custom-Header: FUZZ" -w /usr/share/wordlists/dirb/common.txt
    350 
    351 # Fuzz with status code and length filtering
    352 gobuster fuzz -u http://10.10.10.100/FUZZ -w /usr/share/wordlists/dirb/common.txt \
    353   -b 404,403 --exclude-length 0
    354 ```
    355 
    356 ## 5. Cloud Storage Enumeration
    357 
    358 ### AWS S3 Buckets
    359 
    360 ```bash
    361 # Basic S3 bucket enumeration
    362 gobuster s3 -w /usr/share/seclists/Discovery/Web-Content/bucket-names.txt
    363 
    364 # With debug output
    365 gobuster s3 -w /usr/share/seclists/Discovery/Web-Content/bucket-names.txt --debug
    366 ```
    367 
    368 ### Google Cloud Storage Buckets
    369 
    370 ```bash
    371 # Basic GCS enumeration
    372 gobuster gcs -w /usr/share/seclists/Discovery/Web-Content/bucket-names.txt
    373 
    374 # With debug
    375 gobuster gcs -w /usr/share/seclists/Discovery/Web-Content/bucket-names.txt --debug
    376 ```
    377 
    378 > **Note —** Both modes check for publicly accessible buckets by name. They don't confirm read/write access — just existence. Useful during OSINT and external reconnaissance.
    379 
    380 ## 6. TFTP Enumeration
    381 
    382 ```bash
    383 gobuster tftp -s 10.10.10.100 -w /usr/share/seclists/Discovery/TFTP/common.txt
    384 ```
    385 
    386 | Flag | Short | Description |
    387 |------|-------|-------------|
    388 | `--server <ip>` | `-s` | TFTP server address |
    389 | `--wordlist <file>` | `-w` | Wordlist of filenames to check |
    390 
    391 ## Pattern Files
    392 
    393 Pattern files multiply each wordlist entry with templated variations. Create a file with `{GOBUSTER}` as the placeholder:
    394 
    395 ```text
    396 # patterns.txt
    397 {GOBUSTER}/v1
    398 {GOBUSTER}/v2
    399 {GOBUSTER}/v3
    400 ```
    401 
    402 ```bash
    403 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -p patterns.txt
    404 ```
    405 
    406 If the wordlist contains `api`, Gobuster tests `/api/v1`, `/api/v2`, `/api/v3`. Use with caution — this multiplies the total number of requests.
    407 
    408 ## Recommended Wordlists
    409 
    410 ### SecLists (`sudo apt install seclists`)
    411 
    412 | Purpose | Path |
    413 |---------|------|
    414 | General directories | `/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt` |
    415 | General files | `/usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt` |
    416 | Large directory list | `/usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt` |
    417 | Common (small/fast) | `/usr/share/seclists/Discovery/Web-Content/common.txt` |
    418 | API endpoints | `/usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt` |
    419 | Subdomains — top 5k | `/usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt` |
    420 | Subdomains — top 20k | `/usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt` |
    421 | Subdomains — top 110k | `/usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt` |
    422 | Subdomains — bitquark 100k | `/usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt` |
    423 | Parameter names | `/usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt` |
    424 | Bucket names | `/usr/share/seclists/Discovery/Web-Content/bucket-names.txt` |
    425 | CGI scripts | `/usr/share/seclists/Discovery/Web-Content/CGIs.txt` |
    426 | IIS-specific | `/usr/share/seclists/Discovery/Web-Content/IIS.fuzz.txt` |
    427 
    428 ### Dirb (built-in on Kali)
    429 
    430 | Purpose | Path |
    431 |---------|------|
    432 | Common | `/usr/share/wordlists/dirb/common.txt` |
    433 | Big | `/usr/share/wordlists/dirb/big.txt` |
    434 | Small | `/usr/share/wordlists/dirb/small.txt` |
    435 | Vulns — Apache | `/usr/share/wordlists/dirb/vulns/apache.txt` |
    436 | Vulns — IIS | `/usr/share/wordlists/dirb/vulns/iis.txt` |
    437 | Vulns — Tomcat | `/usr/share/wordlists/dirb/vulns/tomcat.txt` |
    438 
    439 ### Dirbuster
    440 
    441 | Purpose | Path |
    442 |---------|------|
    443 | Small | `/usr/share/wordlists/dirbuster/directory-list-2.3-small.txt` |
    444 | Medium | `/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt` |
    445 | Lowercase medium | `/usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt` |
    446 
    447 ## Extension Stacking by Tech Stack
    448 
    449 When enumerating files, match extensions to the target technology:
    450 
    451 ```bash
    452 # PHP stack
    453 -x php,phps,php5,phtml,phar,inc,bak
    454 
    455 # ASP/.NET stack
    456 -x asp,aspx,ashx,asmx,config,dll
    457 
    458 # Java stack
    459 -x jsp,jspx,do,action,jsf,faces
    460 
    461 # Node/JS stack
    462 -x js,json,ts,mjs
    463 
    464 # Python stack
    465 -x py,pyc,wsgi
    466 
    467 # General backup/config files (always worth trying)
    468 -x bak,old,orig,save,swp,txt,conf,config,xml,yml,yaml,env,log,sql,db,zip,tar.gz
    469 ```
    470 
    471 ## Advanced Tips & Tricks
    472 
    473 ### Wildcard Handling
    474 
    475 If the target returns valid responses for every request (wildcard), Gobuster will detect this and stop. To override:
    476 
    477 ```bash
    478 # Force continue on wildcard (dir mode v3.8+)
    479 gobuster dir -u http://10.10.10.100 -w wordlist.txt --force
    480 
    481 # Better approach: filter by the wildcard response size
    482 gobuster dir -u http://10.10.10.100 -w wordlist.txt --exclude-length 4523
    483 ```
    484 
    485 ### Combining with Other Tools
    486 
    487 ```bash
    488 # Generate a custom wordlist from the target using cewl, then feed to gobuster
    489 cewl http://10.10.10.100 -d 2 -m 5 -w custom_wordlist.txt
    490 gobuster dir -u http://10.10.10.100 -w custom_wordlist.txt -x php,html
    491 
    492 # Pipe found URLs to httpx for probing
    493 gobuster dir -u http://10.10.10.100 -w wordlist.txt -q --no-error | httpx -silent
    494 
    495 # Chain with nuclei for vulnerability scanning on discovered paths
    496 gobuster dir -u http://10.10.10.100 -w wordlist.txt -q -o paths.txt
    497 cat paths.txt | nuclei -t cves/
    498 ```
    499 
    500 ### Rate Limiting & Stealth
    501 
    502 ```bash
    503 # Slow and quiet (2 threads, 1 second delay)
    504 gobuster dir -u http://10.10.10.100 -w wordlist.txt -t 2 --delay 1s
    505 
    506 # Random user agent to evade basic fingerprinting
    507 gobuster dir -u http://10.10.10.100 -w wordlist.txt --random-agent
    508 
    509 # Custom user agent to blend in
    510 gobuster dir -u http://10.10.10.100 -w wordlist.txt \
    511   -a "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
    512 ```
    513 
    514 ### Recursive Enumeration
    515 
    516 Gobuster does **not** natively support recursion. Chain scans manually:
    517 
    518 ```bash
    519 # Step 1: Initial sweep
    520 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -o initial.txt
    521 
    522 # Step 2: Drill into discovered directories
    523 gobuster dir -u http://10.10.10.100/admin -w /usr/share/wordlists/dirb/common.txt -o admin_results.txt
    524 gobuster dir -u http://10.10.10.100/uploads -w /usr/share/wordlists/dirb/common.txt -o uploads_results.txt
    525 ```
    526 
    527 > **Tip — If you need native recursion:** Use **feroxbuster** (Rust-based, recursive by default) or **dirsearch** (Python, built-in recursion).
    528 
    529 ### mTLS / Client Certificates
    530 
    531 For targets requiring mutual TLS authentication (v3.3+):
    532 
    533 ```bash
    534 # Using PEM files
    535 gobuster dir -u https://10.10.10.100 -w wordlist.txt \
    536   --client-cert-pem client.pem \
    537   --client-cert-pem-key client-key.pem
    538 
    539 # Using P12 file (v3.7+ supports SHA256 HMAC P12s from openssl3)
    540 gobuster dir -u https://10.10.10.100 -w wordlist.txt \
    541   --client-cert-p12 client.p12 \
    542   --client-cert-p12-password 'P@ssw0rd'
    543 ```
    544 
    545 ## Quick Reference — Common Workflows
    546 
    547 ### HTB / CTF Initial Enumeration
    548 
    549 ```bash
    550 # Step 1: Quick directory sweep
    551 gobuster dir -u http://target.htb -w /usr/share/seclists/Discovery/Web-Content/common.txt \
    552   -x php,html,txt -t 40 -o initial_scan.txt
    553 
    554 # Step 2: VHost discovery (get a baseline response length first, then exclude it)
    555 gobuster vhost -u http://target.htb \
    556   -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \
    557   --domain target.htb --append-domain -t 40 \
    558   --exclude-length <baseline_length>
    559 
    560 # Step 3: Deeper scan on interesting paths
    561 gobuster dir -u http://target.htb/app \
    562   -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
    563   -x php -t 40 -o deep_scan.txt
    564 
    565 # Step 4: API enumeration if applicable
    566 gobuster dir -u http://target.htb/api \
    567   -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt \
    568   -x json -t 40
    569 ```
    570 
    571 ### Web Application Pentest
    572 
    573 ```bash
    574 # Admin panel hunting
    575 gobuster dir -u http://target.com \
    576   -w /usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt \
    577   -x php,html -s 200,301,302 -t 30 -o admin_hunt.txt
    578 
    579 # Backup and config file discovery
    580 gobuster dir -u http://target.com \
    581   -w /usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt \
    582   -x bak,old,conf,config,env,sql,zip,tar.gz,swp -t 30
    583 
    584 # Parameter fuzzing
    585 gobuster fuzz -u "http://target.com/page.php?FUZZ=1" \
    586   -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt \
    587   -b 404 --exclude-length 0
    588 ```
    589 
    590 ### Bug Bounty Recon
    591 
    592 ```bash
    593 # Subdomain discovery with IP resolution
    594 gobuster dns -d target.com \
    595   -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt \
    596   -t 50 -i -o subdomains.txt
    597 
    598 # Vhost sweep against discovered infrastructure
    599 gobuster vhost -u http://<target-ip> \
    600   -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt \
    601   --domain target.com --append-domain -t 40
    602 
    603 # S3 bucket enumeration with company-related names
    604 gobuster s3 -w company_wordlist.txt --debug
    605 ```
    606 
    607 ## Troubleshooting
    608 
    609 | Problem | Solution |
    610 |---------|----------|
    611 | Wildcard detected, scan aborts | Use `--force` (v3.8+) or `--exclude-length` to filter the wildcard response |
    612 | Flooded with 403 responses | Blacklist with `-b 403`, try `--random-agent`, or adjust User-Agent |
    613 | Scan is too slow | Increase `-t 50` (or higher — test what the target handles) |
    614 | TLS / certificate errors | Add `-k` to skip verification |
    615 | Connection refused / timeout | Increase `--timeout`, reduce `-t`, add `--delay` |
    616 | No results found | Try different wordlists, add `-x` extensions, verify the base URL |
    617 | False positives everywhere | Use `--exclude-length` to filter by response body size |
    618 | Progress bar garbled in piped output | v3.7+ auto-disables progress on redirect; or use `-z` manually |
    619 | "Permission Denied" from target | Reduce thread count, add `--delay`, use `--random-agent` |
    620 
    621 ## Version History (Notable Changes)
    622 
    623 | Version | Key Changes |
    624 |---------|-------------|
    625 | **v3.8.2** | Fix expanded mode showing full URL |
    626 | **v3.8** | `--exclude-hostname-length` flag, `--force` flag in dir mode, fix query parameter fuzzing |
    627 | **v3.7** | New CLI library, `--debug` replaces `--verbose`, `--interface`/`--local-ip` params, TLS renegotiation support, TCP DNS protocol, Host header fuzzing in fuzz mode, auto-disable progress on redirected output, proxy+vhost warning, `--check-cname` replaces `--show-cname` |
    628 | **v3.6** | `--wordlist-offset`, `--exclude-length` supports ranges, `--no-fqdn` in DNS mode |
    629 | **v3.5** | Status code ranges (e.g. `200,300-305,404`) |
    630 | **v3.4** | TLS 1.0/1.1 support, TFTP mode added |
    631 | **v3.3** | mTLS client certificates, extensions from file (`-X`), fuzz POST body/headers/basic auth, `--no-canonicalize-headers` |
    632 | **v3.2** | GCS bucket enumeration, `--retry` on timeout, colour output |
    633 | **v3.1** | S3 bucket enumeration, fuzz mode, pattern files, `--method` flag |
    634 
    635 ## See Also
    636 
    637 | Tool | Language | Key Advantage |
    638 |------|----------|---------------|
    639 | **feroxbuster** | Rust | Native recursion, auto-filtering, content-based deduplication |
    640 | **ffuf** | Go | Multiple `FUZZ` keywords, advanced filtering (size/words/lines/regex), matcher chaining |
    641 | **dirsearch** | Python | Built-in recursion, smart wordlist handling, extension substitution |
    642 | **wfuzz** | Python | Versatile fuzzer, encoders/decoders, complex filtering |
    643 
    644 Based on Gobuster v3.8.2 — https://github.com/OJ/gobuster