当前位置:网站首页>[directory blasting tool] information collection stage: robots.txt, Yujian, dirsearch, dirb, gobuster
[directory blasting tool] information collection stage: robots.txt, Yujian, dirsearch, dirb, gobuster
2022-07-25 13:53:00 【Black zone (rise)】
Catalog
One 、robots.txt
1.1、 brief introduction :
Talking about catalogue , The first one should think of checking robots.txt file
1.2、 understand :
Two 、 Mitsurugi
2.1、 download :
You can find , Don't put links here
2.2、 Use :
Something that can be seen at a glance
3、 ... and 、dirsearch
3.1、 download :
kail It's self-contained
GitHub - maurosoria/dirsearch: Web path scanner
https://github.com/maurosoria/dirsearchPython 3.7 And above
If it's in Windows Download it
After opening and using , Tips : Missing required dependencies
Then input Y, Installation
3.2、 Based on using :
dirsearch.py [-u|--url] target( Specifically URL) [-e|--extensions] extensions( Expand ) [options]
-u Appoint url
-e Specify the website language
-w You can add your own dictionary ( With path )
-r Recursive blasting ( Find a directory , Blast after the catalogue )
--random-agents agent ( The agent directory is uesr-agents.txt in , You can add )
……
Four 、Dirb
4.1、 brief introduction :
effect :
Information collection tools (kail Bring their own )
Purpose :
Dictionary based web Directory scanning tool , Find existing ( Hidden )Web object
Method :
Yes Web The server initiates a dictionary based attack and analyzes the data in response . Use recursion to get more directories , Support for agents and http Authentication restricted websites
4.2、 Use :
Basics :
Format :dirb <url_base> [<wordlist_file(s)>] [options]
Parameters effect -a Set up user-agent -p<proxy[:port]> Setting agent -c Set up cookie -z Add millisecond delay , Avoid floods -o Output results -X Add a suffix after each dictionary -H Add request header -i Case insensitive search scanning :
Basic scanning :
dirb Add the goal URL
Search for specific files ( Here for php)
dirb The goal is URL -X .php
output to a file ( Here for 1.txt)
dirb The goal is URL -o 1.txt
Speed delay ( Here is 100us)
dirb The goal is URL -z 100
HTTP Authorize scanning
dirb The goal is URL -u username:password
……
5、 ... and 、Gobuster
5.1、 brief introduction :
GO language-written
To the directory 、 file 、DNS and VHost And so on
dir: The traditional blasting mode ;
dns:DNS Subdomain explosion mode ;
vhost: Virtual host burst mode
5.2、 download :
Releases · OJ/gobuster · GitHub
https://github.com/OJ/gobuster/releases
边栏推荐
猜你喜欢

嵌入式代码如何进行重构?

LabVIEW的内部错误

Practice of online problem feedback module (13): realize multi parameter paging query list

leetcode--四数相加II

Brush questions - luogu-p1089 Jinjin savings plan

Amd epyc 9664 flagship specification exposure: 96 core 192 threads 480MB cache 3.8ghz frequency

2022年下半年软考初级程序员备考

Workplace "digital people" don't eat or sleep 007 work system, can you "roll" them?

window unbutu20 LTS apt,wget 安装时 DNS 解析错误

Esp32 connects to Alibaba cloud mqtt IOT platform
随机推荐
What is your revenue rank among global developers in 2022?
IM system - some common problems of message streaming
LabVIEW的内部错误
刷题-洛谷-P1046 陶陶摘苹果
JS array indexof includes sort() colon sort quick sort de duplication and random sample random
How can information security engineers prepare for the soft exam in the second half of 2022?
2022年下半年软考信息安全工程师如何备考?
Canal realizes MySQL data synchronization
2271. 毯子覆盖的最多白色砖块数 ●●
Immortal software in the computer that I don't want to delete all my life
Talk about your understanding of hashcode and equals methods?
Business analysis report and data visualization report of CDA level1 knowledge point summary
Uncaught SyntaxError: Octal literals are not allowed in strict mode.
刷题-洛谷-P1161 开灯
Lesson of C function without brackets
Tm1637 four digit LED display module Arduino driver with second dot
刷题-洛谷-P1146 硬币翻转
【力扣】1030.距离顺序排列矩阵单元格
@wrap 装饰器
MXNet对DenseNet(稠密连接网络)的实现
https://blog.csdn.net/qq_53079406/article/details/125898777?spm=1001.2014.3001.5501