To be familiar with the system architecture of the target website, it is essential to know which directories are available on the website.
To awvs and burp large-scale scanning tools, you can also perform directory scanning. However, I personally feel that it is far from a professional scanning tool.
0x01 dirbuster
Introduction: dirbuster is a directory and hidden file developed by OWASP (Open Web software security project-Open Web Application Security Project) to detect web servers.
JDK must be installed in the computer to run Java.
1. configuration instructions
Click Options-advanced options to open the following configuration page:
Here, you can set the file type not to scan, Set automatic login in case of forms, and add the HTTP header (cookie ......),
Proxy Settings, timeout link settings, default thread, dictionary, and extension settings
If you have time, try your own tricks.
2. scan test
Build a local Dede station and directly open the ingress
In step 1, you can also select the pure brute-force cracking mode, with a low hit rate. In contrast, fuzzy testing is easier to use.
(Giggle ~) There is a small error above. In Step 1, you should enter/dedecms5.7/{dir} in the directory under the target site. If you are not aware of this, you will find it ~
Otherwise, the directory in 127.0.0.1: 8080 is scanned.
3. scan results
This is the list of local scan directories. Click Treeview to view the directory tree by yourself.
0x02 Yu Jian
First background scanning artifact in China
You don't need to configure or fill in the website. You only need to have a few points,
Simple and rude. I still hope that Yu Jian's other works will be used in the case of my and other dishes.
Summary:
As mentioned in the previous article, we can manually scan robots.txt for the contents, and maybe the background will be placed in it.
In other words, when the scanning result of a scanner is not satisfactory, we can use two scanners together. Tools are dead, so you must learn how to use them flexibly!
"Security Tools" directory scan dirbuster and yujian