当前位置:网站首页>[directory blasting tool] information collection stage: robots.txt, Yujian, dirsearch, dirb, gobuster
[directory blasting tool] information collection stage: robots.txt, Yujian, dirsearch, dirb, gobuster
2022-07-25 13:53:00 【Black zone (rise)】
Catalog
One 、robots.txt
1.1、 brief introduction :
Talking about catalogue , The first one should think of checking robots.txt file
1.2、 understand :
Two 、 Mitsurugi
2.1、 download :
You can find , Don't put links here
2.2、 Use :
Something that can be seen at a glance
3、 ... and 、dirsearch
3.1、 download :
kail It's self-contained
GitHub - maurosoria/dirsearch: Web path scanner
https://github.com/maurosoria/dirsearchPython 3.7 And above
If it's in Windows Download it
After opening and using , Tips : Missing required dependencies
Then input Y, Installation
3.2、 Based on using :
dirsearch.py [-u|--url] target( Specifically URL) [-e|--extensions] extensions( Expand ) [options]
-u Appoint url
-e Specify the website language
-w You can add your own dictionary ( With path )
-r Recursive blasting ( Find a directory , Blast after the catalogue )
--random-agents agent ( The agent directory is uesr-agents.txt in , You can add )
……
Four 、Dirb
4.1、 brief introduction :
effect :
Information collection tools (kail Bring their own )
Purpose :
Dictionary based web Directory scanning tool , Find existing ( Hidden )Web object
Method :
Yes Web The server initiates a dictionary based attack and analyzes the data in response . Use recursion to get more directories , Support for agents and http Authentication restricted websites
4.2、 Use :
Basics :
Format :dirb <url_base> [<wordlist_file(s)>] [options]
Parameters effect -a Set up user-agent -p<proxy[:port]> Setting agent -c Set up cookie -z Add millisecond delay , Avoid floods -o Output results -X Add a suffix after each dictionary -H Add request header -i Case insensitive search scanning :
Basic scanning :
dirb Add the goal URL
Search for specific files ( Here for php)
dirb The goal is URL -X .php
output to a file ( Here for 1.txt)
dirb The goal is URL -o 1.txt
Speed delay ( Here is 100us)
dirb The goal is URL -z 100
HTTP Authorize scanning
dirb The goal is URL -u username:password
……
5、 ... and 、Gobuster
5.1、 brief introduction :
GO language-written
To the directory 、 file 、DNS and VHost And so on
dir: The traditional blasting mode ;
dns:DNS Subdomain explosion mode ;
vhost: Virtual host burst mode
5.2、 download :
Releases · OJ/gobuster · GitHub
https://github.com/OJ/gobuster/releases
边栏推荐
- Lesson of C function without brackets
- 2022年下半年软考信息安全工程师如何备考?
- Application engineering safety monitoring of wireless vibrating wire acquisition instrument
- 【Platform IO编译Hifive1-revB】*** [.pio\build\hifive1-revb\src\setupGPIO.o] Error 1的解决办法
- Business analysis report and data visualization report of CDA level1 knowledge point summary
- 2022全球开发者中,你的收入排多少?
- [server data recovery] HP EVA server storage raid information power loss data recovery
- JS array indexof includes sort() colon sort quick sort de duplication and random sample random
- window unbutu20 LTS apt,wget 安装时 DNS 解析错误
- Explain the precision of floating point numbers in detail
猜你喜欢

Brush questions - Luogu -p1059 clear random number

Multidimensional pivoting analysis of CDA level1 knowledge points summary

Use of Bluetooth function of vs wireless vibrating wire acquisition instrument

Esp32 connects to Alibaba cloud mqtt IOT platform

Brush questions - Luogu -p1085 unhappy Jinjin
![[force buckle] 645. Wrong set](/img/0a/143d8996cbae9921652c4d4fb31046.png)
[force buckle] 645. Wrong set

【力扣】645.错误的集合

Brush questions - Luogu -p1151 sub number integer

刷题-洛谷-P1151 子数整数

ADB connects to Xiaomi mobile phone via Wi Fi
随机推荐
Hcip day 9 notes
Internal error of LabVIEW
Talk about your understanding of hashcode and equals methods?
I2C can also be powered on by bus!
Workplace "digital people" don't eat or sleep 007 work system, can you "roll" them?
Acquisition data transmission mode and online monitoring system of wireless acquisition instrument for vibrating wire sensor of engineering instrument
Nodejs link MySQL error: Er_ NOT_ SUPPORTED_ AUTH_ MODEError: ER_ NOT_ SUPPORTED_ AUTH_ MODE
刷题-洛谷-P1059 明明的随机数
Stay on Alibaba cloud mqtt IOT platform
Working principle of Lora to 4G and gateway repeater
Write an esp32 Watchdog with Arduino
IM system - some common problems of message streaming
Error of Tencent cloud [100007] this env is not enable anonymous login
GCD details
手里有点钱可以投资哪些理财产品?
飞盘局有多快乐?2022年轻人新潮运动报告
Leetcode1 -- sum of two numbers
Hcip day 10 notes
百度搜索打击盗版网文站点,SEOer应该关注哪些问题?
Sword finger offer special assault edition day 10
https://blog.csdn.net/qq_53079406/article/details/125898777?spm=1001.2014.3001.5501