← All cheat sheets

GOBUSTER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

INSTALLATION#

go install github.com/OJ/gobuster/v3@latest
apt install gobuster    # Kali/Debian
brew install gobuster   # macOS

MODES#

dir     Directory/file enumeration
dns     DNS subdomain enumeration
vhost   Virtual host enumeration
fuzz    Fuzzing mode
s3      S3 bucket enumeration
gcs     Google Cloud Storage enumeration
tftp    TFTP enumeration

DIRECTORY MODE (dir)#

# Basic usage
gobuster dir -u http://target.com -w /usr/share/wordlists/dirb/common.txt

# Common options
-u URL          Target URL
-w WORDLIST     Path to wordlist
-t THREADS      Number of threads (default 10)
-o OUTPUT       Output file
-x EXTENSIONS   File extensions to search (e.g., php,html,txt)
-s STATUSCODES  Positive status codes (default 200,204,301,302,307,401,403)
-b STATUSCODES  Negative status codes to exclude
-k              Skip SSL certificate verification
-a USERAGENT    User-Agent string
-c COOKIE       Cookie string
-H HEADER       HTTP header (format: "Name: Value")
-p PROXY        Proxy to use
-r              Follow redirects
-n              Don't print status codes
-q              Quiet mode (no banner)
-v              Verbose mode
-e              Print full URLs
--delay         Delay between requests
--timeout       HTTP timeout (default 10s)
--no-error      Don't display errors
--wildcard      Force wildcard processing

# Examples
gobuster dir -u http://target.com -w wordlist.txt -x php,html,txt

gobuster dir -u http://target.com -w wordlist.txt -t 50 -o results.txt

gobuster dir -u http://target.com -w wordlist.txt -x php -s 200,301 -b 404

gobuster dir -u http://target.com -w wordlist.txt -c "session=abc123"

gobuster dir -u http://target.com -w wordlist.txt -H "Authorization: Bearer token"

gobuster dir -u https://target.com -w wordlist.txt -k

# With authentication
gobuster dir -u http://target.com -w wordlist.txt -U username -P password

DNS MODE (dns)#

# Basic usage
gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt

# Common options
-d DOMAIN       Target domain
-w WORDLIST     Path to wordlist
-t THREADS      Number of threads
-o OUTPUT       Output file
-r RESOLVER     DNS resolver (e.g., 8.8.8.8)
-c              Show CNAME records
-i              Show IP addresses
--wildcard      Force wildcard processing
--timeout       DNS resolver timeout

# Examples
gobuster dns -d target.com -w wordlist.txt -i

gobuster dns -d target.com -w wordlist.txt -r 8.8.8.8

gobuster dns -d target.com -w wordlist.txt -c -i -o subdomains.txt

VHOST MODE (vhost)#

# Basic usage
gobuster vhost -u http://target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt

# Common options
-u URL          Target URL
-w WORDLIST     Path to wordlist
-t THREADS      Number of threads
-o OUTPUT       Output file
--append-domain Append main domain to words

# Examples
gobuster vhost -u http://target.com -w wordlist.txt

gobuster vhost -u http://target.com -w wordlist.txt --append-domain

FUZZ MODE (fuzz)#

# Basic usage
gobuster fuzz -u http://target.com/FUZZ -w wordlist.txt

# Uses FUZZ as placeholder
gobuster fuzz -u http://target.com/api/FUZZ/users -w wordlist.txt

# Options similar to dir mode

S3 MODE (s3)#

# Basic usage
gobuster s3 -w bucket-names.txt

# Options
-w WORDLIST     Bucket name wordlist
-m MAXFILES     Max files to list per bucket
-t THREADS      Number of threads

WORDLISTS#

# Directory enumeration
/usr/share/wordlists/dirb/common.txt
/usr/share/wordlists/dirb/big.txt
/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
/usr/share/wordlists/dirbuster/directory-list-2.3-small.txt
/usr/share/seclists/Discovery/Web-Content/common.txt
/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
/usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt

# DNS/Subdomain enumeration
/usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
/usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt
/usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt
/usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt

# File extensions
/usr/share/seclists/Discovery/Web-Content/web-extensions.txt

PRACTICAL EXAMPLES#

# Basic directory scan
gobuster dir -u http://target.com -w /usr/share/wordlists/dirb/common.txt

# Scan for specific extensions
gobuster dir -u http://target.com -w /usr/share/wordlists/dirb/common.txt -x php,bak,txt,html,js

# Fast scan with more threads
gobuster dir -u http://target.com -w /usr/share/wordlists/dirb/big.txt -t 100

# Scan with cookies (authenticated)
gobuster dir -u http://target.com -w wordlist.txt -c "PHPSESSID=abc123; token=xyz"

# Scan behind proxy
gobuster dir -u http://target.com -w wordlist.txt -p http://127.0.0.1:8080

# Subdomain enumeration
gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -t 50

# Virtual host discovery
gobuster vhost -u http://target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt

# API endpoint discovery
gobuster dir -u http://target.com/api -w /usr/share/seclists/Discovery/Web-Content/api/objects.txt -x json

# WordPress specific
gobuster dir -u http://target.com -w /usr/share/seclists/Discovery/Web-Content/CMS/wordpress.fuzz.txt

# Backup files
gobuster dir -u http://target.com -w wordlist.txt -x bak,old,backup,~,swp

OUTPUT PARSING#

# Filter results
gobuster dir -u http://target.com -w wordlist.txt -o results.txt
grep "Status: 200" results.txt
grep -v "Status: 404" results.txt

# Extract URLs only
gobuster dir -u http://target.com -w wordlist.txt -e -o results.txt
grep "http" results.txt | cut -d" " -f1

TIPS#

- Start with smaller wordlists, scale up if needed
- Use appropriate thread count (10-50 typically)
- Add common extensions: -x php,html,txt,bak,old
- Check for backup extensions: -x bak,backup,old,~
- Use -k for HTTPS with invalid certs
- Save output with -o for later analysis
- Use --no-error to reduce noise
- Adjust --timeout for slow targets
- Use -r to follow redirects when needed

COMPARISON WITH OTHER TOOLS#

gobuster  - Fast, Go-based, multiple modes
dirb      - Classic, slower, good for CTF
dirbuster - GUI, Java-based
ffuf      - Fast, flexible fuzzer
feroxbuster - Recursive by default, Rust-based
wfuzz     - Flexible, good for fuzzing

ALTERNATIVES#

ffuf -u http://target.com/FUZZ -w wordlist.txt
feroxbuster -u http://target.com -w wordlist.txt
dirb http://target.com wordlist.txt
wfuzz -c -z file,wordlist.txt http://target.com/FUZZ