GOBUSTER
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
INSTALLATION#
go install github.com/OJ/gobuster/v3@latest apt install gobuster # Kali/Debian brew install gobuster # macOS
MODES#
dir Directory/file enumeration dns DNS subdomain enumeration vhost Virtual host enumeration fuzz Fuzzing mode s3 S3 bucket enumeration gcs Google Cloud Storage enumeration tftp TFTP enumeration
DIRECTORY MODE (dir)#
# Basic usage gobuster dir -u http://target.com -w /usr/share/wordlists/dirb/common.txt # Common options -u URL Target URL -w WORDLIST Path to wordlist -t THREADS Number of threads (default 10) -o OUTPUT Output file -x EXTENSIONS File extensions to search (e.g., php,html,txt) -s STATUSCODES Positive status codes (default 200,204,301,302,307,401,403) -b STATUSCODES Negative status codes to exclude -k Skip SSL certificate verification -a USERAGENT User-Agent string -c COOKIE Cookie string -H HEADER HTTP header (format: "Name: Value") -p PROXY Proxy to use -r Follow redirects -n Don't print status codes -q Quiet mode (no banner) -v Verbose mode -e Print full URLs --delay Delay between requests --timeout HTTP timeout (default 10s) --no-error Don't display errors --wildcard Force wildcard processing # Examples gobuster dir -u http://target.com -w wordlist.txt -x php,html,txt gobuster dir -u http://target.com -w wordlist.txt -t 50 -o results.txt gobuster dir -u http://target.com -w wordlist.txt -x php -s 200,301 -b 404 gobuster dir -u http://target.com -w wordlist.txt -c "session=abc123" gobuster dir -u http://target.com -w wordlist.txt -H "Authorization: Bearer token" gobuster dir -u https://target.com -w wordlist.txt -k # With authentication gobuster dir -u http://target.com -w wordlist.txt -U username -P password
DNS MODE (dns)#
# Basic usage gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt # Common options -d DOMAIN Target domain -w WORDLIST Path to wordlist -t THREADS Number of threads -o OUTPUT Output file -r RESOLVER DNS resolver (e.g., 8.8.8.8) -c Show CNAME records -i Show IP addresses --wildcard Force wildcard processing --timeout DNS resolver timeout # Examples gobuster dns -d target.com -w wordlist.txt -i gobuster dns -d target.com -w wordlist.txt -r 8.8.8.8 gobuster dns -d target.com -w wordlist.txt -c -i -o subdomains.txt
VHOST MODE (vhost)#
# Basic usage gobuster vhost -u http://target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt # Common options -u URL Target URL -w WORDLIST Path to wordlist -t THREADS Number of threads -o OUTPUT Output file --append-domain Append main domain to words # Examples gobuster vhost -u http://target.com -w wordlist.txt gobuster vhost -u http://target.com -w wordlist.txt --append-domain
FUZZ MODE (fuzz)#
# Basic usage gobuster fuzz -u http://target.com/FUZZ -w wordlist.txt # Uses FUZZ as placeholder gobuster fuzz -u http://target.com/api/FUZZ/users -w wordlist.txt # Options similar to dir mode
S3 MODE (s3)#
# Basic usage gobuster s3 -w bucket-names.txt # Options -w WORDLIST Bucket name wordlist -m MAXFILES Max files to list per bucket -t THREADS Number of threads
WORDLISTS#
# Directory enumeration /usr/share/wordlists/dirb/common.txt /usr/share/wordlists/dirb/big.txt /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt /usr/share/wordlists/dirbuster/directory-list-2.3-small.txt /usr/share/seclists/Discovery/Web-Content/common.txt /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt /usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt # DNS/Subdomain enumeration /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt # File extensions /usr/share/seclists/Discovery/Web-Content/web-extensions.txt
PRACTICAL EXAMPLES#
# Basic directory scan gobuster dir -u http://target.com -w /usr/share/wordlists/dirb/common.txt # Scan for specific extensions gobuster dir -u http://target.com -w /usr/share/wordlists/dirb/common.txt -x php,bak,txt,html,js # Fast scan with more threads gobuster dir -u http://target.com -w /usr/share/wordlists/dirb/big.txt -t 100 # Scan with cookies (authenticated) gobuster dir -u http://target.com -w wordlist.txt -c "PHPSESSID=abc123; token=xyz" # Scan behind proxy gobuster dir -u http://target.com -w wordlist.txt -p http://127.0.0.1:8080 # Subdomain enumeration gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -t 50 # Virtual host discovery gobuster vhost -u http://target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt # API endpoint discovery gobuster dir -u http://target.com/api -w /usr/share/seclists/Discovery/Web-Content/api/objects.txt -x json # WordPress specific gobuster dir -u http://target.com -w /usr/share/seclists/Discovery/Web-Content/CMS/wordpress.fuzz.txt # Backup files gobuster dir -u http://target.com -w wordlist.txt -x bak,old,backup,~,swp
OUTPUT PARSING#
# Filter results gobuster dir -u http://target.com -w wordlist.txt -o results.txt grep "Status: 200" results.txt grep -v "Status: 404" results.txt # Extract URLs only gobuster dir -u http://target.com -w wordlist.txt -e -o results.txt grep "http" results.txt | cut -d" " -f1
TIPS#
- Start with smaller wordlists, scale up if needed - Use appropriate thread count (10-50 typically) - Add common extensions: -x php,html,txt,bak,old - Check for backup extensions: -x bak,backup,old,~ - Use -k for HTTPS with invalid certs - Save output with -o for later analysis - Use --no-error to reduce noise - Adjust --timeout for slow targets - Use -r to follow redirects when needed
COMPARISON WITH OTHER TOOLS#
gobuster - Fast, Go-based, multiple modes dirb - Classic, slower, good for CTF dirbuster - GUI, Java-based ffuf - Fast, flexible fuzzer feroxbuster - Recursive by default, Rust-based wfuzz - Flexible, good for fuzzing
ALTERNATIVES#
ffuf -u http://target.com/FUZZ -w wordlist.txt feroxbuster -u http://target.com -w wordlist.txt dirb http://target.com wordlist.txt wfuzz -c -z file,wordlist.txt http://target.com/FUZZ