Download as pdf or txt
Download as pdf or txt
You are on page 1of 2

DIRB – Directory Buster

 Nearly all websites use folders and


shortcuts to organise data
 Question: If your favourite company
was named ACME, what might their
‘admin’ web URLs look like?
 admin.acme.com?
 www.acme.com/admin?
 hidden.acme.com/admin?
 DIRB automates this scanning
 Spidering for hidden/unknown pages
and websites
 Is this ‘active’ or ‘passive’ scanning?
 Active: don’t scan without permission
DIRB wordlists

 What words does DIRB use?


 Wordlists are commonly reused
within certain systems
 Have an apache server? Use the
apache wordlist
 cold-fusion server?
 Web server with CGI enabled?

 5 minute exercise
 Start Web For Pentester and
Webgoat
 Use DIRB to probe both websites
 Have more time? Open the
apache.txt wordlist and view it

You might also like