Gobuster
Gobuster: Open Source Directory Enumeration Tool
An open source command line tool for conducting directory and file enumeration on web servers, finding hidden directories and files with sensitive information
What is Gobuster?
Gobuster is an open source command line tool for performing forced browsing on web servers. It is typically used by security professionals and pen testers to enumerate directories and files that exist on a target web server but are not linked or easily discoverable.
Some key features and uses of Gobuster include:
- Can brute force directories and filenames using custom wordlists
- Useful for discovering backup files, configuration files, hidden admin panels, and more
- Can identify directories that don't require authentication
- Extensible through custom plugins
- Easy to install and run, works on Linux, Mac OSX, and Windows
Gobuster is often used during the reconnaissance and discovery phases of pen testing to uncover hidden parts of web applications. It complements other web scanning tools by focusing specifically on directory and file enumeration via forced browsing.
Gobuster Features
Features
- Directory and file brute forcing
- Recursive brute forcing
- Uses wordlists for brute forcing
- Can brute force multiple targets
- Has various modes like directory/file, DNS and VHost enumeration
- Extensible via custom plugins
Pricing
- Open Source
Pros
Cons
Official Links
Reviews & Ratings
Login to ReviewThe Best Gobuster Alternatives
View all Gobuster alternatives with detailed comparison →
Top Security & Privacy and Web Application Security and other similar apps like Gobuster
DirBuster
Dirstalk