"Security Tools" directory scan dirbuster and yujian

Source: Internet
Author: User

To be familiar with the system architecture of the target website, it is essential to know which directories are available on the website.

To awvs and burp large-scale scanning tools, you can also perform directory scanning. However, I personally feel that it is far from a professional scanning tool.

 

0x01 dirbuster

Introduction: dirbuster is a directory and hidden file developed by OWASP (Open Web software security project-Open Web Application Security Project) to detect web servers.

JDK must be installed in the computer to run Java.

1. configuration instructions

Click Options-advanced options to open the following configuration page:

      

Here, you can set the file type not to scan, Set automatic login in case of forms, and add the HTTP header (cookie ......),

Proxy Settings, timeout link settings, default thread, dictionary, and extension settings

If you have time, try your own tricks.

2. scan test

Build a local Dede station and directly open the ingress

    

In step 1, you can also select the pure brute-force cracking mode, with a low hit rate. In contrast, fuzzy testing is easier to use.

(Giggle ~) There is a small error above. In Step 1, you should enter/dedecms5.7/{dir} in the directory under the target site. If you are not aware of this, you will find it ~

Otherwise, the directory in 127.0.0.1: 8080 is scanned.

3. scan results

This is the list of local scan directories. Click Treeview to view the directory tree by yourself.

    

      

0x02 Yu Jian

First background scanning artifact in China

You don't need to configure or fill in the website. You only need to have a few points,

    

Simple and rude. I still hope that Yu Jian's other works will be used in the case of my and other dishes.

 

    Summary:

As mentioned in the previous article, we can manually scan robots.txt for the contents, and maybe the background will be placed in it.

In other words, when the scanning result of a scanner is not satisfactory, we can use two scanners together. Tools are dead, so you must learn how to use them flexibly!

    

  

 

"Security Tools" directory scan dirbuster and yujian

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.