当前位置:网站首页>[directory blasting tool] information collection stage: robots.txt, Yujian, dirsearch, dirb, gobuster
[directory blasting tool] information collection stage: robots.txt, Yujian, dirsearch, dirb, gobuster
2022-07-25 13:53:00 【Black zone (rise)】
Catalog
One 、robots.txt
1.1、 brief introduction :
Talking about catalogue , The first one should think of checking robots.txt file
1.2、 understand :
Two 、 Mitsurugi
2.1、 download :
You can find , Don't put links here
2.2、 Use :
Something that can be seen at a glance
3、 ... and 、dirsearch
3.1、 download :
kail It's self-contained
GitHub - maurosoria/dirsearch: Web path scanner
https://github.com/maurosoria/dirsearchPython 3.7 And above
If it's in Windows Download it
After opening and using , Tips : Missing required dependencies
Then input Y, Installation
3.2、 Based on using :
dirsearch.py [-u|--url] target( Specifically URL) [-e|--extensions] extensions( Expand ) [options]
-u Appoint url
-e Specify the website language
-w You can add your own dictionary ( With path )
-r Recursive blasting ( Find a directory , Blast after the catalogue )
--random-agents agent ( The agent directory is uesr-agents.txt in , You can add )
……
Four 、Dirb
4.1、 brief introduction :
effect :
Information collection tools (kail Bring their own )
Purpose :
Dictionary based web Directory scanning tool , Find existing ( Hidden )Web object
Method :
Yes Web The server initiates a dictionary based attack and analyzes the data in response . Use recursion to get more directories , Support for agents and http Authentication restricted websites
4.2、 Use :
Basics :
Format :dirb <url_base> [<wordlist_file(s)>] [options]
Parameters effect -a Set up user-agent -p<proxy[:port]> Setting agent -c Set up cookie -z Add millisecond delay , Avoid floods -o Output results -X Add a suffix after each dictionary -H Add request header -i Case insensitive search scanning :
Basic scanning :
dirb Add the goal URL
Search for specific files ( Here for php)
dirb The goal is URL -X .php
output to a file ( Here for 1.txt)
dirb The goal is URL -o 1.txt
Speed delay ( Here is 100us)
dirb The goal is URL -z 100
HTTP Authorize scanning
dirb The goal is URL -u username:password
……
5、 ... and 、Gobuster
5.1、 brief introduction :
GO language-written
To the directory 、 file 、DNS and VHost And so on
dir: The traditional blasting mode ;
dns:DNS Subdomain explosion mode ;
vhost: Virtual host burst mode
5.2、 download :
Releases · OJ/gobuster · GitHub
https://github.com/OJ/gobuster/releases
边栏推荐
- Business data analysis of CDA level1 knowledge point summary
- Brush questions - Luogu -p1151 sub number integer
- 埃拉托斯特尼筛法
- Advantages of wireless relay acquisition instrument and wireless network for engineering monitoring
- 刷题-洛谷-P1047 校门外的树
- G027-op-ins-rhel-04 RedHat openstack creates a customized qcow2 format image
- Internal error of LabVIEW
- Redux usage and analysis
- 伯克利博士『机器学习工程』大实话;AI副总裁『2022 ML就业市场』分析;半导体创业公司大列表;大规模视频人脸属性数据集;前沿论文 | ShowMeAI资讯日报
- [force buckle] 645. Wrong set
猜你喜欢

【目录爆破工具】信息收集阶段:robots.txt、御剑、dirsearch、Dirb、Gobuster

GCD details

Brush questions - Luogu -p1059 clear random number

What is your revenue rank among global developers in 2022?

Practice of online problem feedback module (13): realize multi parameter paging query list

刷题-洛谷-P1151 子数整数

QGIS loading online map: Gaode, Tiandi map, etc

Working mode and sleep mode of nlm5 series wireless vibrating wire sensor acquisition instrument

2022年下半年软考初级程序员备考

Applet H5 get mobile number scheme
随机推荐
[force buckle] 645. Wrong set
Leetcode 113. path sum II
Data analysis interview records 1-5
命名空间与库
刷题-洛谷-P1152 欢乐的跳
Leetcode -- addition of four numbers II
Namespaces and libraries
Canvas judgment content is empty
Advantages of wireless relay acquisition instrument and wireless network for engineering monitoring
【力扣】645.错误的集合
GCD details
What should I do if the high-level MySQL server cannot be installed and I forget the password (MySQL 8.0.29)?
Brush questions - Luogu -p1046 Tao Tao picking apples
From input URL to web page display
刷题-洛谷-P1161 开灯
6.27 uniapp project history
[configure hifive1 revb] the device manager does not recognize the port, and can not connect to j-link via USB
Brush questions - Luogu -p1161 turn on the light
伯克利博士『机器学习工程』大实话;AI副总裁『2022 ML就业市场』分析;半导体创业公司大列表;大规模视频人脸属性数据集;前沿论文 | ShowMeAI资讯日报
MySQL and Navicat installation and stepping on pits
