gobuster.md (26545B)
1 --- 2 title: "Gobuster" 3 description: "Gobuster dir, dns, vhost and s3 brute-forcing modes with wordlist and status-code options." 4 category: enumeration 5 tags: [enumeration, web, brute-force] 6 tools: [Gobuster] 7 difficulty: beginner 8 updated: "2026-08-09" 9 source: "vault:Tools/gobuster.md" 10 --- 11 12 # Gobuster 13 14 > **Gobuster** — Fast brute-force enumeration tool written in Go (v3.8.2, Sep 2025). Authors: OJ Reeves (`@TheColonial`) & Christian Mehlmauer (`@firefart`). 15 > Capabilities: directory/file, DNS subdomain, virtual host, S3 bucket, GCS bucket, TFTP, and generic fuzzing enumeration. 16 17 ## Installation 18 19 ```bash 20 # Kali Linux (pre-installed in default metapackage) 21 sudo apt install gobuster 22 23 # Go install (requires Go 1.24+) 24 go install github.com/OJ/gobuster/v3@latest 25 26 # Build from source 27 git clone https://github.com/OJ/gobuster.git 28 cd gobuster 29 go mod tidy 30 go build 31 32 # Docker 33 docker pull ghcr.io/oj/gobuster:latest 34 docker run --rm -it ghcr.io/oj/gobuster:latest dir -u https://target.com -w /usr/share/wordlists/dirb/common.txt 35 ``` 36 37 ## Modes Overview 38 39 | Mode | Command | Purpose | 40 |------|---------|---------| 41 | `dir` | `gobuster dir` | Directory & file brute-forcing on web servers | 42 | `dns` | `gobuster dns` | DNS subdomain enumeration | 43 | `vhost` | `gobuster vhost` | Virtual host discovery via `Host` header manipulation | 44 | `fuzz` | `gobuster fuzz` | Generic fuzzing — replaces `FUZZ` keyword in URL, headers, and request body | 45 | `s3` | `gobuster s3` | AWS S3 bucket enumeration | 46 | `gcs` | `gobuster gcs` | Google Cloud Storage bucket enumeration | 47 | `tftp` | `gobuster tftp` | TFTP file enumeration | 48 49 ```bash 50 # Getting help 51 gobuster -h # General help 52 gobuster help dir # Help for a specific mode 53 gobuster dir --help # Alternative help syntax 54 ``` 55 56 ## Global Flags (Apply to All Modes) 57 58 | Flag | Short | Description | 59 |------|-------|-------------| 60 | `--wordlist <path>` | `-w` | Path to the wordlist (set to `-` to read from STDIN) | 61 | `--threads <int>` | `-t` | Number of concurrent threads (default: `10`) | 62 | `--output <file>` | `-o` | Write results to a file | 63 | `--delay <duration>` | | Delay between requests per thread (e.g. `500ms`, `1s`, `1500ms`) | 64 | `--pattern <file>` | `-p` | File containing replacement patterns using `{GOBUSTER}` placeholder | 65 | `--wordlist-offset <int>` | | Resume from a given position in the wordlist | 66 | `--debug` | | Enable debug output (replaces the old `--verbose` flag in v3.7+) | 67 | `--quiet` | `-q` | Suppress banner and noise | 68 | `--no-progress` | `-z` | Don't display progress indicator | 69 | `--no-error` | | Suppress error messages | 70 | `--no-color` | | Disable colour output | 71 72 > **Note — v3.7+ CLI changes:** From v3.7 onwards, Gobuster switched to a new CLI library. The `--verbose` flag was replaced by `--debug`. Some short flags were also reassigned. Always check `gobuster <mode> --help` on your installed version. 73 74 ## 1. Directory & File Enumeration (`dir`) 75 76 The most commonly used mode. Brute-forces URIs (directories and files) on web servers. 77 78 ### All `dir` Mode Flags 79 80 | Flag | Short | Description | 81 |------|-------|-------------| 82 | `--url <url>` | `-u` | **Required.** Target URL | 83 | `--extensions <exts>` | `-x` | File extensions to search for (comma-separated, e.g. `php,html,txt`) | 84 | `--extensions-file <file>` | `-X` | Read extensions from a file | 85 | `--status-codes <codes>` | `-s` | Positive status codes to include. Supports ranges (e.g. `200,300-400,404`) | 86 | `--status-codes-blacklist <codes>` | `-b` | Negative status codes to exclude. Supports ranges. (default: `404`) | 87 | `--exclude-length <lengths>` | | Exclude responses by content length. Supports comma-separated values and ranges (e.g. `0,203-206,1234`) | 88 | `--method <method>` | `-m` | HTTP method to use (default: `GET`) | 89 | `--cookies <string>` | `-c` | Cookies to include in requests | 90 | `--headers <header>` | `-H` | Custom HTTP headers (repeatable: `-H 'Header1: val1' -H 'Header2: val2'`) | 91 | `--useragent <string>` | `-a` | Set the User-Agent string | 92 | `--random-agent` | | Use a random User-Agent string per request | 93 | `--username <user>` | `-U` | Username for HTTP Basic Auth | 94 | `--password <pass>` | `-P` | Password for HTTP Basic Auth | 95 | `--proxy <url>` | | Proxy to use (`http(s)://host:port` or `socks5://host:port`) | 96 | `--follow-redirect` | `-r` | Follow HTTP redirects | 97 | `--no-tls-validation` | `-k` | Skip TLS certificate verification | 98 | `--timeout <duration>` | | HTTP request timeout (default: `10s`) | 99 | `--add-slash` | `-f` | Append `/` to each request | 100 | `--expanded` | `-e` | Print full URLs in output | 101 | `--no-status` | `-n` | Don't print status codes | 102 | `--hide-length` | | Hide the body length in output | 103 | `--discover-backup` | `-d` | On finding a file, also search for backup file variations | 104 | `--no-canonicalize-headers` | | Send HTTP header names as-is (don't canonicalize) | 105 | `--retry` | | Retry on request timeout | 106 | `--retry-attempts <int>` | | Number of retries (default: `3`) | 107 | `--force` | | Continue execution even if precheck errors occur (v3.8+) | 108 | `--client-cert-p12 <file>` | | P12 file for mTLS client certificates | 109 | `--client-cert-p12-password <pass>` | | Password for the P12 file | 110 | `--client-cert-pem <file>` | | PEM public key for mTLS | 111 | `--client-cert-pem-key <file>` | | PEM private key for mTLS (must have no password) | 112 113 ### Practical Examples 114 115 ```bash 116 # Basic directory enumeration 117 gobuster dir -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt 118 119 # Search for specific file extensions 120 gobuster dir -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt \ 121 -x php,html,txt,bak,old,conf,xml,json 122 123 # Extensions loaded from a file 124 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \ 125 -X /home/kali/extensions.txt 126 127 # With authentication cookie (e.g. post-login enumeration) 128 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/big.txt \ 129 -c "PHPSESSID=abc123def456" -x php 130 131 # HTTP Basic Auth 132 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \ 133 -U admin -P password123 134 135 # Custom header (e.g. JWT / Bearer token) 136 gobuster dir -u http://10.10.10.100/api -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt \ 137 -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIs..." 138 139 # Follow redirects and skip TLS errors 140 gobuster dir -u https://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -r -k 141 142 # Proxy through Burp Suite 143 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \ 144 --proxy http://127.0.0.1:8080 145 146 # SOCKS5 proxy (e.g. through ligolo-ng or SSH tunnel) 147 gobuster dir -u http://172.16.1.10 -w /usr/share/wordlists/dirb/common.txt \ 148 --proxy socks5://127.0.0.1:1080 149 150 # Filter false positives by excluding response lengths 151 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \ 152 --exclude-length 0,4523 153 154 # Only show specific status codes (supports ranges) 155 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \ 156 -s 200,301,302 157 158 # Blacklist status codes 159 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \ 160 -b 403,404 161 162 # Random user agent to evade basic fingerprinting 163 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \ 164 --random-agent 165 166 # High threads with rate limiting 167 gobuster dir -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt \ 168 -t 50 --delay 100ms 169 170 # Auto-discover backup files alongside regular enumeration 171 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -d 172 173 # POST method enumeration 174 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -m POST 175 176 # Resume a scan from a specific wordlist offset 177 gobuster dir -u http://10.10.10.100 -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt \ 178 --wordlist-offset 5000 179 180 # Force continue even if precheck fails (v3.8+) 181 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt --force 182 183 # Read wordlist from STDIN (piping) 184 cat custom_wordlist.txt | gobuster dir -u http://10.10.10.100 -w - 185 186 # mTLS client certificate authentication 187 gobuster dir -u https://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt \ 188 --client-cert-pem client.pem --client-cert-pem-key client-key.pem 189 190 # Save output to file 191 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -o results.txt 192 ``` 193 194 ## 2. DNS Subdomain Enumeration (`dns`) 195 196 Discovers subdomains via DNS resolution. Requires the target domain to be resolvable. 197 198 ### All `dns` Mode Flags 199 200 | Flag | Short | Description | 201 |------|-------|-------------| 202 | `--domain <domain>` | `-d` | **Required.** Target domain | 203 | `--resolver <server>` | `-r` | Custom DNS resolver (e.g. `8.8.8.8` or `8.8.8.8:53`) | 204 | `--show-ips` | `-i` | Show resolved IP addresses in results | 205 | `--show-cname` / `--check-cname` | `-c` | Show CNAME records (cannot be combined with `-i`). Renamed to `--check-cname` in v3.7+ | 206 | `--timeout <duration>` | | DNS resolver timeout (default: `1s`) | 207 | `--wildcard` | | Force continued operation when a wildcard DNS record is detected | 208 | `--no-fqdn` | | Don't automatically append a trailing dot — disables system search domains (can speed up scans, v3.6+) | 209 210 ### Practical Examples 211 212 ```bash 213 # Basic subdomain enumeration 214 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt 215 216 # Show resolved IP addresses alongside subdomains 217 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt -i 218 219 # Use a custom DNS resolver (bypass internal/split-horizon DNS) 220 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \ 221 -r 1.1.1.1 222 223 # Show CNAME records (useful for subdomain takeover identification) 224 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -c 225 226 # Force operation on wildcard domains 227 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt --wildcard 228 229 # High thread count for large wordlists 230 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -t 50 231 232 # Disable FQDN trailing dot (skip system search domains for speed) 233 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt \ 234 --no-fqdn -t 50 235 236 # Save results 237 gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \ 238 -i -o subdomains.txt 239 ``` 240 241 > **Tip — DNS enumeration pre-requisite:** Ensure the target domain actually resolves. If behind a firewall or using split-horizon DNS, you may need to specify a resolver (`-r`) that has visibility into the target's DNS zone. 242 243 ## 3. Virtual Host Discovery (`vhost`) 244 245 Sends HTTP requests with different `Host:` headers to find virtual hosts on a web server. Unlike DNS mode, this does **not** require DNS resolution — it works directly against the server IP. 246 247 ### All `vhost` Mode Flags 248 249 | Flag | Short | Description | 250 |------|-------|-------------| 251 | `--url <url>` | `-u` | **Required.** Target URL (typically use the IP address) | 252 | `--domain <domain>` | | Domain to append to wordlist entries | 253 | `--append-domain` | | Append the main domain from the URL to each wordlist word | 254 | `--exclude-length <lengths>` | | Exclude responses by content length (comma-separated, supports ranges) | 255 | `--method <method>` | `-m` | HTTP method (default: `GET`) | 256 | `--cookies <string>` | `-c` | Cookies for requests | 257 | `--headers <header>` | `-H` | Custom headers (repeatable) | 258 | `--follow-redirect` | `-r` | Follow redirects | 259 | `--no-tls-validation` | `-k` | Skip TLS verification | 260 | `--proxy <url>` | | Proxy to use | 261 | `--random-agent` | | Use random User-Agent | 262 | `--useragent <string>` | `-a` | Set User-Agent | 263 | `--username <user>` | `-U` | HTTP Basic Auth username | 264 | `--password <pass>` | `-P` | HTTP Basic Auth password | 265 | `--timeout <duration>` | | HTTP timeout (default: `10s`) | 266 | `--retry` | | Retry on timeout | 267 | `--retry-attempts <int>` | | Number of retries (default: `3`) | 268 | `--no-canonicalize-headers` | | Don't canonicalize header names | 269 | `--client-cert-*` | | mTLS client certificate options (same as dir mode) | 270 271 ### Practical Examples 272 273 ```bash 274 # Basic vhost discovery — with --append-domain to build FQDN Host headers 275 gobuster vhost -u http://10.10.10.100 \ 276 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \ 277 --domain target.htb --append-domain 278 279 # Filter false positives by excluding a known baseline response length 280 gobuster vhost -u http://10.10.10.100 \ 281 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \ 282 --domain target.htb --append-domain --exclude-length 301 283 284 # Over HTTPS with TLS skip 285 gobuster vhost -u https://10.10.10.100 \ 286 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \ 287 --domain target.htb --append-domain -k 288 289 # High thread count 290 gobuster vhost -u http://10.10.10.100 \ 291 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt \ 292 --domain target.htb --append-domain -t 50 293 ``` 294 295 > **Important — VHost vs DNS mode:** 296 > - Use **DNS mode** to discover subdomains via actual DNS resolution. 297 > - Use **VHost mode** when the server hosts multiple sites on the same IP and you need to discover them by manipulating the `Host` header. 298 > - **VHost is the go-to for HTB/CTF targets** where you've added the base domain to `/etc/hosts` and want to find additional virtual hosts. 299 > - From v3.7+, Gobuster warns you if `--append-domain` might have been forgotten. 300 301 ## 4. Fuzz Mode (`fuzz`) 302 303 The most flexible mode. Replaces the keyword `FUZZ` in the URL, headers, and request body with wordlist entries. 304 305 ### Key `fuzz` Mode Flags 306 307 Fuzz mode shares most HTTP flags with `dir` mode, plus: 308 309 | Feature | Flag | Description | 310 |---------|------|-------------| 311 | URL fuzzing | `-u` | Include `FUZZ` in the URL | 312 | Header fuzzing | `-H` | Include `FUZZ` in header values | 313 | Body fuzzing | `-d` | Include `FUZZ` in POST body data (v3.3+) | 314 | Host header fuzzing | `-H "Host: FUZZ.domain"` | Supported natively in v3.7+ | 315 | Exclude lengths | `--exclude-length` | Filter false positives | 316 | Blacklist codes | `-b` | Exclude status codes | 317 318 ### Practical Examples 319 320 ```bash 321 # Fuzz URL paths 322 gobuster fuzz -u http://10.10.10.100/FUZZ -w /usr/share/wordlists/dirb/common.txt 323 324 # Fuzz API endpoints 325 gobuster fuzz -u http://10.10.10.100/api/v1/FUZZ \ 326 -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt 327 328 # Fuzz URL parameters (parameter name discovery) 329 gobuster fuzz -u "http://10.10.10.100/page?FUZZ=test" \ 330 -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt 331 332 # Fuzz parameter values 333 gobuster fuzz -u "http://10.10.10.100/page?id=FUZZ" \ 334 -w /usr/share/seclists/Fuzzing/4-digits-0000-9999.txt 335 336 # Fuzz the Host header (alternative to vhost mode, more control) 337 gobuster fuzz -u http://10.10.10.100 \ 338 -H "Host: FUZZ.target.htb" \ 339 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \ 340 --exclude-length 1234 341 342 # Fuzz POST body data (v3.3+) 343 gobuster fuzz -u http://10.10.10.100/login \ 344 -d "username=admin&password=FUZZ" \ 345 -w /usr/share/seclists/Passwords/Common-Credentials/10k-most-common.txt 346 347 # Fuzz custom headers 348 gobuster fuzz -u http://10.10.10.100 \ 349 -H "X-Custom-Header: FUZZ" -w /usr/share/wordlists/dirb/common.txt 350 351 # Fuzz with status code and length filtering 352 gobuster fuzz -u http://10.10.10.100/FUZZ -w /usr/share/wordlists/dirb/common.txt \ 353 -b 404,403 --exclude-length 0 354 ``` 355 356 ## 5. Cloud Storage Enumeration 357 358 ### AWS S3 Buckets 359 360 ```bash 361 # Basic S3 bucket enumeration 362 gobuster s3 -w /usr/share/seclists/Discovery/Web-Content/bucket-names.txt 363 364 # With debug output 365 gobuster s3 -w /usr/share/seclists/Discovery/Web-Content/bucket-names.txt --debug 366 ``` 367 368 ### Google Cloud Storage Buckets 369 370 ```bash 371 # Basic GCS enumeration 372 gobuster gcs -w /usr/share/seclists/Discovery/Web-Content/bucket-names.txt 373 374 # With debug 375 gobuster gcs -w /usr/share/seclists/Discovery/Web-Content/bucket-names.txt --debug 376 ``` 377 378 > **Note —** Both modes check for publicly accessible buckets by name. They don't confirm read/write access — just existence. Useful during OSINT and external reconnaissance. 379 380 ## 6. TFTP Enumeration 381 382 ```bash 383 gobuster tftp -s 10.10.10.100 -w /usr/share/seclists/Discovery/TFTP/common.txt 384 ``` 385 386 | Flag | Short | Description | 387 |------|-------|-------------| 388 | `--server <ip>` | `-s` | TFTP server address | 389 | `--wordlist <file>` | `-w` | Wordlist of filenames to check | 390 391 ## Pattern Files 392 393 Pattern files multiply each wordlist entry with templated variations. Create a file with `{GOBUSTER}` as the placeholder: 394 395 ```text 396 # patterns.txt 397 {GOBUSTER}/v1 398 {GOBUSTER}/v2 399 {GOBUSTER}/v3 400 ``` 401 402 ```bash 403 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -p patterns.txt 404 ``` 405 406 If the wordlist contains `api`, Gobuster tests `/api/v1`, `/api/v2`, `/api/v3`. Use with caution — this multiplies the total number of requests. 407 408 ## Recommended Wordlists 409 410 ### SecLists (`sudo apt install seclists`) 411 412 | Purpose | Path | 413 |---------|------| 414 | General directories | `/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt` | 415 | General files | `/usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt` | 416 | Large directory list | `/usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt` | 417 | Common (small/fast) | `/usr/share/seclists/Discovery/Web-Content/common.txt` | 418 | API endpoints | `/usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt` | 419 | Subdomains — top 5k | `/usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt` | 420 | Subdomains — top 20k | `/usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt` | 421 | Subdomains — top 110k | `/usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt` | 422 | Subdomains — bitquark 100k | `/usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt` | 423 | Parameter names | `/usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt` | 424 | Bucket names | `/usr/share/seclists/Discovery/Web-Content/bucket-names.txt` | 425 | CGI scripts | `/usr/share/seclists/Discovery/Web-Content/CGIs.txt` | 426 | IIS-specific | `/usr/share/seclists/Discovery/Web-Content/IIS.fuzz.txt` | 427 428 ### Dirb (built-in on Kali) 429 430 | Purpose | Path | 431 |---------|------| 432 | Common | `/usr/share/wordlists/dirb/common.txt` | 433 | Big | `/usr/share/wordlists/dirb/big.txt` | 434 | Small | `/usr/share/wordlists/dirb/small.txt` | 435 | Vulns — Apache | `/usr/share/wordlists/dirb/vulns/apache.txt` | 436 | Vulns — IIS | `/usr/share/wordlists/dirb/vulns/iis.txt` | 437 | Vulns — Tomcat | `/usr/share/wordlists/dirb/vulns/tomcat.txt` | 438 439 ### Dirbuster 440 441 | Purpose | Path | 442 |---------|------| 443 | Small | `/usr/share/wordlists/dirbuster/directory-list-2.3-small.txt` | 444 | Medium | `/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt` | 445 | Lowercase medium | `/usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt` | 446 447 ## Extension Stacking by Tech Stack 448 449 When enumerating files, match extensions to the target technology: 450 451 ```bash 452 # PHP stack 453 -x php,phps,php5,phtml,phar,inc,bak 454 455 # ASP/.NET stack 456 -x asp,aspx,ashx,asmx,config,dll 457 458 # Java stack 459 -x jsp,jspx,do,action,jsf,faces 460 461 # Node/JS stack 462 -x js,json,ts,mjs 463 464 # Python stack 465 -x py,pyc,wsgi 466 467 # General backup/config files (always worth trying) 468 -x bak,old,orig,save,swp,txt,conf,config,xml,yml,yaml,env,log,sql,db,zip,tar.gz 469 ``` 470 471 ## Advanced Tips & Tricks 472 473 ### Wildcard Handling 474 475 If the target returns valid responses for every request (wildcard), Gobuster will detect this and stop. To override: 476 477 ```bash 478 # Force continue on wildcard (dir mode v3.8+) 479 gobuster dir -u http://10.10.10.100 -w wordlist.txt --force 480 481 # Better approach: filter by the wildcard response size 482 gobuster dir -u http://10.10.10.100 -w wordlist.txt --exclude-length 4523 483 ``` 484 485 ### Combining with Other Tools 486 487 ```bash 488 # Generate a custom wordlist from the target using cewl, then feed to gobuster 489 cewl http://10.10.10.100 -d 2 -m 5 -w custom_wordlist.txt 490 gobuster dir -u http://10.10.10.100 -w custom_wordlist.txt -x php,html 491 492 # Pipe found URLs to httpx for probing 493 gobuster dir -u http://10.10.10.100 -w wordlist.txt -q --no-error | httpx -silent 494 495 # Chain with nuclei for vulnerability scanning on discovered paths 496 gobuster dir -u http://10.10.10.100 -w wordlist.txt -q -o paths.txt 497 cat paths.txt | nuclei -t cves/ 498 ``` 499 500 ### Rate Limiting & Stealth 501 502 ```bash 503 # Slow and quiet (2 threads, 1 second delay) 504 gobuster dir -u http://10.10.10.100 -w wordlist.txt -t 2 --delay 1s 505 506 # Random user agent to evade basic fingerprinting 507 gobuster dir -u http://10.10.10.100 -w wordlist.txt --random-agent 508 509 # Custom user agent to blend in 510 gobuster dir -u http://10.10.10.100 -w wordlist.txt \ 511 -a "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 512 ``` 513 514 ### Recursive Enumeration 515 516 Gobuster does **not** natively support recursion. Chain scans manually: 517 518 ```bash 519 # Step 1: Initial sweep 520 gobuster dir -u http://10.10.10.100 -w /usr/share/wordlists/dirb/common.txt -o initial.txt 521 522 # Step 2: Drill into discovered directories 523 gobuster dir -u http://10.10.10.100/admin -w /usr/share/wordlists/dirb/common.txt -o admin_results.txt 524 gobuster dir -u http://10.10.10.100/uploads -w /usr/share/wordlists/dirb/common.txt -o uploads_results.txt 525 ``` 526 527 > **Tip — If you need native recursion:** Use **feroxbuster** (Rust-based, recursive by default) or **dirsearch** (Python, built-in recursion). 528 529 ### mTLS / Client Certificates 530 531 For targets requiring mutual TLS authentication (v3.3+): 532 533 ```bash 534 # Using PEM files 535 gobuster dir -u https://10.10.10.100 -w wordlist.txt \ 536 --client-cert-pem client.pem \ 537 --client-cert-pem-key client-key.pem 538 539 # Using P12 file (v3.7+ supports SHA256 HMAC P12s from openssl3) 540 gobuster dir -u https://10.10.10.100 -w wordlist.txt \ 541 --client-cert-p12 client.p12 \ 542 --client-cert-p12-password 'P@ssw0rd' 543 ``` 544 545 ## Quick Reference — Common Workflows 546 547 ### HTB / CTF Initial Enumeration 548 549 ```bash 550 # Step 1: Quick directory sweep 551 gobuster dir -u http://target.htb -w /usr/share/seclists/Discovery/Web-Content/common.txt \ 552 -x php,html,txt -t 40 -o initial_scan.txt 553 554 # Step 2: VHost discovery (get a baseline response length first, then exclude it) 555 gobuster vhost -u http://target.htb \ 556 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt \ 557 --domain target.htb --append-domain -t 40 \ 558 --exclude-length <baseline_length> 559 560 # Step 3: Deeper scan on interesting paths 561 gobuster dir -u http://target.htb/app \ 562 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ 563 -x php -t 40 -o deep_scan.txt 564 565 # Step 4: API enumeration if applicable 566 gobuster dir -u http://target.htb/api \ 567 -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt \ 568 -x json -t 40 569 ``` 570 571 ### Web Application Pentest 572 573 ```bash 574 # Admin panel hunting 575 gobuster dir -u http://target.com \ 576 -w /usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt \ 577 -x php,html -s 200,301,302 -t 30 -o admin_hunt.txt 578 579 # Backup and config file discovery 580 gobuster dir -u http://target.com \ 581 -w /usr/share/seclists/Discovery/Web-Content/raft-medium-files.txt \ 582 -x bak,old,conf,config,env,sql,zip,tar.gz,swp -t 30 583 584 # Parameter fuzzing 585 gobuster fuzz -u "http://target.com/page.php?FUZZ=1" \ 586 -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt \ 587 -b 404 --exclude-length 0 588 ``` 589 590 ### Bug Bounty Recon 591 592 ```bash 593 # Subdomain discovery with IP resolution 594 gobuster dns -d target.com \ 595 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt \ 596 -t 50 -i -o subdomains.txt 597 598 # Vhost sweep against discovered infrastructure 599 gobuster vhost -u http://<target-ip> \ 600 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt \ 601 --domain target.com --append-domain -t 40 602 603 # S3 bucket enumeration with company-related names 604 gobuster s3 -w company_wordlist.txt --debug 605 ``` 606 607 ## Troubleshooting 608 609 | Problem | Solution | 610 |---------|----------| 611 | Wildcard detected, scan aborts | Use `--force` (v3.8+) or `--exclude-length` to filter the wildcard response | 612 | Flooded with 403 responses | Blacklist with `-b 403`, try `--random-agent`, or adjust User-Agent | 613 | Scan is too slow | Increase `-t 50` (or higher — test what the target handles) | 614 | TLS / certificate errors | Add `-k` to skip verification | 615 | Connection refused / timeout | Increase `--timeout`, reduce `-t`, add `--delay` | 616 | No results found | Try different wordlists, add `-x` extensions, verify the base URL | 617 | False positives everywhere | Use `--exclude-length` to filter by response body size | 618 | Progress bar garbled in piped output | v3.7+ auto-disables progress on redirect; or use `-z` manually | 619 | "Permission Denied" from target | Reduce thread count, add `--delay`, use `--random-agent` | 620 621 ## Version History (Notable Changes) 622 623 | Version | Key Changes | 624 |---------|-------------| 625 | **v3.8.2** | Fix expanded mode showing full URL | 626 | **v3.8** | `--exclude-hostname-length` flag, `--force` flag in dir mode, fix query parameter fuzzing | 627 | **v3.7** | New CLI library, `--debug` replaces `--verbose`, `--interface`/`--local-ip` params, TLS renegotiation support, TCP DNS protocol, Host header fuzzing in fuzz mode, auto-disable progress on redirected output, proxy+vhost warning, `--check-cname` replaces `--show-cname` | 628 | **v3.6** | `--wordlist-offset`, `--exclude-length` supports ranges, `--no-fqdn` in DNS mode | 629 | **v3.5** | Status code ranges (e.g. `200,300-305,404`) | 630 | **v3.4** | TLS 1.0/1.1 support, TFTP mode added | 631 | **v3.3** | mTLS client certificates, extensions from file (`-X`), fuzz POST body/headers/basic auth, `--no-canonicalize-headers` | 632 | **v3.2** | GCS bucket enumeration, `--retry` on timeout, colour output | 633 | **v3.1** | S3 bucket enumeration, fuzz mode, pattern files, `--method` flag | 634 635 ## See Also 636 637 | Tool | Language | Key Advantage | 638 |------|----------|---------------| 639 | **feroxbuster** | Rust | Native recursion, auto-filtering, content-based deduplication | 640 | **ffuf** | Go | Multiple `FUZZ` keywords, advanced filtering (size/words/lines/regex), matcher chaining | 641 | **dirsearch** | Python | Built-in recursion, smart wordlist handling, extension substitution | 642 | **wfuzz** | Python | Versatile fuzzer, encoders/decoders, complex filtering | 643 644 Based on Gobuster v3.8.2 — https://github.com/OJ/gobuster