• Blackhat Pakistan — Ethical Hacking, Hacking Tools & Cybersecurity Tutorials

Gobuster Tutorial 2026 - Fast Directory, DNS and VHOST Brute Forcing

Blackhatpakistan

Administrator
Staff member
Joined
Dec 30, 2024
Messages
399
Reaction score
209
Points
62
Website
blackhatpakistan.net
Points
1,198
USD
1,198
Gobuster is a Go-based content discovery tool that brute forces directories (dir mode), subdomains (dns mode), virtual hosts (vhost mode) and custom parameters (fuzz mode) against a target URL using a wordlist. It runs as a single binary with no runtime dependencies, which is why it ships in every Kali image and survives on minimal VPS boxes where Python tooling breaks.

TL;DR - Pick the mode first (dir for paths, dns for subdomains, vhost for virtual hosts, fuzz for anything injectable), then the wordlist decides your hit rate more than any flag. Start with -t 20 and throttle up, keep -x extensions tight per target, log everything with -o and treat status-code triage (200, 301, 403, 401) as the real skill - not the tool itself.

ceounx.png


INSTALL - ONE BINARY, NO DEPENDENCIES

Kali ships it preinstalled. Everywhere else it is a single binary:

Code:
# Kali

sudo apt update && sudo apt install gobuster

# Any Linux with Go

go install github.com/OJ/gobuster/v3@latest

ls ~/go/bin/gobuster

# Verify the version - modes differ between v3 and older builds

gobuster version

Gobuster v3 reorganized flags compared to v3.0 era builds. The examples here use current v3 syntax: -u for dir mode, -d for dns mode, -h for vhost mode, --wordlist for the list.

THE FOUR MODES AND WHEN TO USE EACH

- dir - paths and endpoints on a web server. The default reconnaissance move: /admin, /backup, /api-docs, /wp-content. Start every HTTP target here.

- dns - subdomain brute force against a zone. Resolves through the target DNS, catches dev., staging., vpn. hosts that never appear in certificate transparency logs.

- vhost - virtual hosts on the same IP. Sends Host headers from the wordlist and watches for response-size shifts - the technique behind finding admin panels behind shared hosting.

- fuzz - the general mode. Fuzz a single position with {{W}} placeholders: paths with extensions, parameter names, subdomain prefixes, header values.

mtb2u8.png


WORDLISTS DECIDE YOUR RESULTS

The tool is the delivery mechanism; the wordlist is the payload. A wrong list produces confident, empty results.

Code:
# Built-in small list - quick sanity pass

gobuster dir -u https://target.com -w /usr/share/wordlists/dirb/common.txt

# Content discovery, medium depth

gobuster dir -u https://target.com \

  -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt

# Subdomains - the two that catch real hosts

gobuster dns -d target.com \

  -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt

# Mutations for vhost discovery - uppercase, backup suffixes

gobuster dir -u https://target.com \

  -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \

  -U -b 404,403

Seclists ships on Kali under /usr/share/seclists. raft-medium-directories hits more often than dirb common because it is built from observed live-server paths, not dictionary words.

FLAGS THAT ACTUALLY MATTER

Code:
# Extensions, one pass instead of five

gobuster dir -u https://target.com -w wordlist.txt -x php,bak,old,env,json

# Recursive discovery - follow discovered directories

gobuster dir -u https://target.com -w wordlist.txt -r

# Status codes to treat as interesting (beyond 200)

gobuster dir -u https://target.com -w wordlist.txt -s 200,204,301,302,307,401,403

# Status codes to ignore (soft-404 noise)

gobuster dir -u https://target.com -w wordlist.txt -b 404,429,500

# URL encoding for parameter fuzzing

gobuster fuzz -u "https://target.com/page?id={{W}}" -w wordlist.txt -q

-s trims the report down to codes you will actually act on. -b silences rate-limit pages that otherwise flood output with fake hits.

RATE TUNING - SPEED WITHOUT BANS

Default thread count is 10. Against anything with a WAF that reads as a burst.

Code:
# Slow start on protected targets

gobuster dir -u https://target.com -w wordlist.txt -t 5 --delay 200ms

# Unprotected internal app - safe to push

gobuster dir -u http://10.10.10.5:8080 -w wordlist.txt -t 50

# Show errors while debugging reachability

gobuster dir -u https://target.com -w wordlist.txt --debug

--delay works in milliseconds. Pair -t 5 with --delay 200ms for targets behind Cloudflare or ModSecurity; that combination stays under most default ban thresholds while still clearing 5000-word lists in minutes.

jgxiyp.png


CLOUDFLARE AND 403 PATTERNS

Everything behind Cloudflare answers with the same soft-404: same length, same status, every path. Raw status filtering lies to you there - compare response sizes instead, and watch for -s returning nothing while wordlist progress claims hits. The deeper fix lives in the Cloudflare bypass workflow: origin IP hunting, host header rotation, and realistic UA strings.

PARSING OUTPUT INTO FINDS

Code:
# Save raw output on every run

gobuster dir -u https://target.com -w wordlist.txt -o results.txt

# Extract only found paths

grep -E "Status: (200|301|403)" results.txt | awk '{print $1}' > found.txt

# Turn hits into a fetch loop

while read path; do

  curl -sk -o /dev/null -w "%{http_code} %{size_download} $path\n" \

    "https://target.com$path"

done < found.txt

The size column in that curl line exposes soft-404s instantly - a 200 that returns the same 4321 bytes for every path is a custom error page, not a find.

fqu4q6.png


COMMON MISTAKES

- Running dir mode with no -x and wondering why backup files never show up - extensions are opt-in, not automatic.

- Trusting every 200 - custom 404 pages return 200 more often than people expect; confirm by requesting a path that cannot exist.

- Tiny wordlists on large targets - 4000 entries is a warmup; raft-large or gobuster's own wordlists exist for a reason.

- Ignoring DNS mode - the interesting target is often staging.target.com with no auth in front of it.

- One-shot enumeration - re-run monthly; content discovery is a habit, not a phase.

FAQ

- Q: Is gobuster faster than dirb or dirbuster? A: Noticeably. The Go implementation handles thousands of concurrent requests where dirb crawls single-threaded, and the memory footprint stays near zero on long runs.

- Q: Why does every path return status 200? A: A soft-404 or wildcard vhost is answering everything. Request /definitely-not-a-real-path-9482 and compare the response size - match means the server lies, switch to size-based filtering.

- Q: dns mode returns nothing but dig works? A: The resolver gobuster uses may differ from yours. Point it with --resolver 1.1.1.1 and confirm the zone actually accepts wildcard queries before blaming the wordlist.

- Q: How do I keep results out of git? A: Write with -o into a dated directory and add it to .gitignore - scan output routinely leaks internal paths, hostnames and parameter names.

RELATED ON BLACKHAT PAKISTAN

OSINT Tools for Beginners - the passive recon that tells you which domains are worth brute forcing.

Nmap Cheat Sheet 2026 - service discovery before you start guessing paths.

Bypass Cloudflare - the origin-finding workflow for when gobuster only sees the proxy.

XSS Tutorial for Beginners - take the parameters gobuster surfaces and test what they reflect.
 
Last edited:
Threads
1,086Threads
Messages
2,157Messages
Members
3,716Members
Latest member
allllalllalll45258Latest member
Top