当前位置:网站首页>[directory blasting tool] information collection stage: robots.txt, Yujian, dirsearch, dirb, gobuster
[directory blasting tool] information collection stage: robots.txt, Yujian, dirsearch, dirb, gobuster
2022-07-25 13:53:00 【Black zone (rise)】
Catalog
One 、robots.txt
1.1、 brief introduction :
Talking about catalogue , The first one should think of checking robots.txt file
1.2、 understand :
Two 、 Mitsurugi
2.1、 download :
You can find , Don't put links here
2.2、 Use :
Something that can be seen at a glance
3、 ... and 、dirsearch
3.1、 download :
kail It's self-contained
GitHub - maurosoria/dirsearch: Web path scanner
https://github.com/maurosoria/dirsearchPython 3.7 And above
If it's in Windows Download it
After opening and using , Tips : Missing required dependencies
Then input Y, Installation
3.2、 Based on using :
dirsearch.py [-u|--url] target( Specifically URL) [-e|--extensions] extensions( Expand ) [options]
-u Appoint url
-e Specify the website language
-w You can add your own dictionary ( With path )
-r Recursive blasting ( Find a directory , Blast after the catalogue )
--random-agents agent ( The agent directory is uesr-agents.txt in , You can add )
……
Four 、Dirb
4.1、 brief introduction :
effect :
Information collection tools (kail Bring their own )
Purpose :
Dictionary based web Directory scanning tool , Find existing ( Hidden )Web object
Method :
Yes Web The server initiates a dictionary based attack and analyzes the data in response . Use recursion to get more directories , Support for agents and http Authentication restricted websites
4.2、 Use :
Basics :
Format :dirb <url_base> [<wordlist_file(s)>] [options]
Parameters effect -a Set up user-agent -p<proxy[:port]> Setting agent -c Set up cookie -z Add millisecond delay , Avoid floods -o Output results -X Add a suffix after each dictionary -H Add request header -i Case insensitive search scanning :
Basic scanning :
dirb Add the goal URL
Search for specific files ( Here for php)
dirb The goal is URL -X .php
output to a file ( Here for 1.txt)
dirb The goal is URL -o 1.txt
Speed delay ( Here is 100us)
dirb The goal is URL -z 100
HTTP Authorize scanning
dirb The goal is URL -u username:password
……
5、 ... and 、Gobuster
5.1、 brief introduction :
GO language-written
To the directory 、 file 、DNS and VHost And so on
dir: The traditional blasting mode ;
dns:DNS Subdomain explosion mode ;
vhost: Virtual host burst mode
5.2、 download :
Releases · OJ/gobuster · GitHub
https://github.com/OJ/gobuster/releases
边栏推荐
- Alibaba mqtt IOT platform "cloud product circulation" practice - the two esp32 achieve remote interoperability through the IOT platform
- Brush questions - Luogu -p1075 prime factor decomposition
- 力扣(LeetCode)205. 同构字符串(2022.07.24)
- Explain the precision of floating point numbers in detail
- 刷题-洛谷-P1150 Peter的烟
- [server data recovery] HP EVA server storage raid information power loss data recovery
- G027-op-ins-rhel-04 RedHat openstack creates a customized qcow2 format image
- redis集群的三种方式
- Gym installation, invocation and registration
- einsum(): operands do not broadcast with remapped shapes [original->remapped]: [1, 144, 20, 17]->[1,
猜你喜欢

运动豪华还是安全豪华?亚洲龙与沃尔沃S60该入手哪款?

Pytest.mark.parameterize and mock use

Brush questions - Luogu -p1151 sub number integer
![Error of Tencent cloud [100007] this env is not enable anonymous login](/img/a2/a209a0d94e3fbf607242c28d87e2dd.png)
Error of Tencent cloud [100007] this env is not enable anonymous login

Internal error of LabVIEW

Brush questions - Luogu -p1059 clear random number

Brush questions - Luogu -p1085 unhappy Jinjin

Audio and video technology development weekly | 255

Engineering monitoring multi-channel vibrating wire sensor wireless acquisition instrument external digital sensor process

leetcode--四数相加II
随机推荐
What problems should SEOER pay attention to when baidu searches and attacks pirated websites?
IM系统-消息流化一些常见问题
Business data analysis of CDA level1 knowledge point summary
刷题-洛谷-P1046 陶陶摘苹果
Redux usage and analysis
Practice of online problem feedback module (13): realize multi parameter paging query list
"Digital security" alert NFT's seven Scams
leetcode--四数相加II
2022全球开发者中,你的收入排多少?
MySQL 01: Source command
Brush questions - Luogu -p1047 trees outside the school gate
@Classmethod decorator
2022年下半年软考初级程序员备考
Brush questions - Luogu -p1152 happy jump
sieve of eratosthenes
leetcode202---快乐数
Applet enterprise red envelope function
JS array indexof includes sort() colon sort quick sort de duplication and random sample random
刷题-洛谷-P1151 子数整数
AQS of concurrent programming
https://blog.csdn.net/qq_53079406/article/details/125898777?spm=1001.2014.3001.5501