- Joined
- Dec 30, 2024
- Messages
- 399
- Reaction score
- 209
- Points
- 62
- Website
- blackhatpakistan.net
- Points
- 1,198
- USD
- 1,198
Gobuster is a Go-based content discovery tool that brute forces directories (dir mode), subdomains (dns mode), virtual hosts (vhost mode) and custom parameters (fuzz mode) against a target URL using a wordlist. It runs as a single binary with no runtime dependencies, which is why it ships in every Kali image and survives on minimal VPS boxes where Python tooling breaks.
TL;DR - Pick the mode first (dir for paths, dns for subdomains, vhost for virtual hosts, fuzz for anything injectable), then the wordlist decides your hit rate more than any flag. Start with -t 20 and throttle up, keep -x extensions tight per target, log everything with -o and treat status-code triage (200, 301, 403, 401) as the real skill - not the tool itself.
INSTALL - ONE BINARY, NO DEPENDENCIES
Kali ships it preinstalled. Everywhere else it is a single binary:
Gobuster v3 reorganized flags compared to v3.0 era builds. The examples here use current v3 syntax: -u for dir mode, -d for dns mode, -h for vhost mode, --wordlist for the list.
THE FOUR MODES AND WHEN TO USE EACH
- dir - paths and endpoints on a web server. The default reconnaissance move: /admin, /backup, /api-docs, /wp-content. Start every HTTP target here.
- dns - subdomain brute force against a zone. Resolves through the target DNS, catches dev., staging., vpn. hosts that never appear in certificate transparency logs.
- vhost - virtual hosts on the same IP. Sends Host headers from the wordlist and watches for response-size shifts - the technique behind finding admin panels behind shared hosting.
- fuzz - the general mode. Fuzz a single position with {{W}} placeholders: paths with extensions, parameter names, subdomain prefixes, header values.
WORDLISTS DECIDE YOUR RESULTS
The tool is the delivery mechanism; the wordlist is the payload. A wrong list produces confident, empty results.
Seclists ships on Kali under /usr/share/seclists. raft-medium-directories hits more often than dirb common because it is built from observed live-server paths, not dictionary words.
FLAGS THAT ACTUALLY MATTER
-s trims the report down to codes you will actually act on. -b silences rate-limit pages that otherwise flood output with fake hits.
RATE TUNING - SPEED WITHOUT BANS
Default thread count is 10. Against anything with a WAF that reads as a burst.
--delay works in milliseconds. Pair -t 5 with --delay 200ms for targets behind Cloudflare or ModSecurity; that combination stays under most default ban thresholds while still clearing 5000-word lists in minutes.
CLOUDFLARE AND 403 PATTERNS
Everything behind Cloudflare answers with the same soft-404: same length, same status, every path. Raw status filtering lies to you there - compare response sizes instead, and watch for -s returning nothing while wordlist progress claims hits. The deeper fix lives in the Cloudflare bypass workflow: origin IP hunting, host header rotation, and realistic UA strings.
PARSING OUTPUT INTO FINDS
The size column in that curl line exposes soft-404s instantly - a 200 that returns the same 4321 bytes for every path is a custom error page, not a find.
COMMON MISTAKES
- Running dir mode with no -x and wondering why backup files never show up - extensions are opt-in, not automatic.
- Trusting every 200 - custom 404 pages return 200 more often than people expect; confirm by requesting a path that cannot exist.
- Tiny wordlists on large targets - 4000 entries is a warmup; raft-large or gobuster's own wordlists exist for a reason.
- Ignoring DNS mode - the interesting target is often staging.target.com with no auth in front of it.
- One-shot enumeration - re-run monthly; content discovery is a habit, not a phase.
FAQ
- Q: Is gobuster faster than dirb or dirbuster? A: Noticeably. The Go implementation handles thousands of concurrent requests where dirb crawls single-threaded, and the memory footprint stays near zero on long runs.
- Q: Why does every path return status 200? A: A soft-404 or wildcard vhost is answering everything. Request /definitely-not-a-real-path-9482 and compare the response size - match means the server lies, switch to size-based filtering.
- Q: dns mode returns nothing but dig works? A: The resolver gobuster uses may differ from yours. Point it with --resolver 1.1.1.1 and confirm the zone actually accepts wildcard queries before blaming the wordlist.
- Q: How do I keep results out of git? A: Write with -o into a dated directory and add it to .gitignore - scan output routinely leaks internal paths, hostnames and parameter names.
RELATED ON BLACKHAT PAKISTAN
OSINT Tools for Beginners - the passive recon that tells you which domains are worth brute forcing.
Nmap Cheat Sheet 2026 - service discovery before you start guessing paths.
Bypass Cloudflare - the origin-finding workflow for when gobuster only sees the proxy.
XSS Tutorial for Beginners - take the parameters gobuster surfaces and test what they reflect.
TL;DR - Pick the mode first (dir for paths, dns for subdomains, vhost for virtual hosts, fuzz for anything injectable), then the wordlist decides your hit rate more than any flag. Start with -t 20 and throttle up, keep -x extensions tight per target, log everything with -o and treat status-code triage (200, 301, 403, 401) as the real skill - not the tool itself.
INSTALL - ONE BINARY, NO DEPENDENCIES
Kali ships it preinstalled. Everywhere else it is a single binary:
Code:
# Kali
sudo apt update && sudo apt install gobuster
# Any Linux with Go
go install github.com/OJ/gobuster/v3@latest
ls ~/go/bin/gobuster
# Verify the version - modes differ between v3 and older builds
gobuster version
Gobuster v3 reorganized flags compared to v3.0 era builds. The examples here use current v3 syntax: -u for dir mode, -d for dns mode, -h for vhost mode, --wordlist for the list.
THE FOUR MODES AND WHEN TO USE EACH
- dir - paths and endpoints on a web server. The default reconnaissance move: /admin, /backup, /api-docs, /wp-content. Start every HTTP target here.
- dns - subdomain brute force against a zone. Resolves through the target DNS, catches dev., staging., vpn. hosts that never appear in certificate transparency logs.
- vhost - virtual hosts on the same IP. Sends Host headers from the wordlist and watches for response-size shifts - the technique behind finding admin panels behind shared hosting.
- fuzz - the general mode. Fuzz a single position with {{W}} placeholders: paths with extensions, parameter names, subdomain prefixes, header values.
WORDLISTS DECIDE YOUR RESULTS
The tool is the delivery mechanism; the wordlist is the payload. A wrong list produces confident, empty results.
Code:
# Built-in small list - quick sanity pass
gobuster dir -u https://target.com -w /usr/share/wordlists/dirb/common.txt
# Content discovery, medium depth
gobuster dir -u https://target.com \
-w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
# Subdomains - the two that catch real hosts
gobuster dns -d target.com \
-w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
# Mutations for vhost discovery - uppercase, backup suffixes
gobuster dir -u https://target.com \
-w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \
-U -b 404,403
Seclists ships on Kali under /usr/share/seclists. raft-medium-directories hits more often than dirb common because it is built from observed live-server paths, not dictionary words.
FLAGS THAT ACTUALLY MATTER
Code:
# Extensions, one pass instead of five
gobuster dir -u https://target.com -w wordlist.txt -x php,bak,old,env,json
# Recursive discovery - follow discovered directories
gobuster dir -u https://target.com -w wordlist.txt -r
# Status codes to treat as interesting (beyond 200)
gobuster dir -u https://target.com -w wordlist.txt -s 200,204,301,302,307,401,403
# Status codes to ignore (soft-404 noise)
gobuster dir -u https://target.com -w wordlist.txt -b 404,429,500
# URL encoding for parameter fuzzing
gobuster fuzz -u "https://target.com/page?id={{W}}" -w wordlist.txt -q
-s trims the report down to codes you will actually act on. -b silences rate-limit pages that otherwise flood output with fake hits.
RATE TUNING - SPEED WITHOUT BANS
Default thread count is 10. Against anything with a WAF that reads as a burst.
Code:
# Slow start on protected targets
gobuster dir -u https://target.com -w wordlist.txt -t 5 --delay 200ms
# Unprotected internal app - safe to push
gobuster dir -u http://10.10.10.5:8080 -w wordlist.txt -t 50
# Show errors while debugging reachability
gobuster dir -u https://target.com -w wordlist.txt --debug
--delay works in milliseconds. Pair -t 5 with --delay 200ms for targets behind Cloudflare or ModSecurity; that combination stays under most default ban thresholds while still clearing 5000-word lists in minutes.
CLOUDFLARE AND 403 PATTERNS
Everything behind Cloudflare answers with the same soft-404: same length, same status, every path. Raw status filtering lies to you there - compare response sizes instead, and watch for -s returning nothing while wordlist progress claims hits. The deeper fix lives in the Cloudflare bypass workflow: origin IP hunting, host header rotation, and realistic UA strings.
PARSING OUTPUT INTO FINDS
Code:
# Save raw output on every run
gobuster dir -u https://target.com -w wordlist.txt -o results.txt
# Extract only found paths
grep -E "Status: (200|301|403)" results.txt | awk '{print $1}' > found.txt
# Turn hits into a fetch loop
while read path; do
curl -sk -o /dev/null -w "%{http_code} %{size_download} $path\n" \
"https://target.com$path"
done < found.txt
The size column in that curl line exposes soft-404s instantly - a 200 that returns the same 4321 bytes for every path is a custom error page, not a find.
COMMON MISTAKES
- Running dir mode with no -x and wondering why backup files never show up - extensions are opt-in, not automatic.
- Trusting every 200 - custom 404 pages return 200 more often than people expect; confirm by requesting a path that cannot exist.
- Tiny wordlists on large targets - 4000 entries is a warmup; raft-large or gobuster's own wordlists exist for a reason.
- Ignoring DNS mode - the interesting target is often staging.target.com with no auth in front of it.
- One-shot enumeration - re-run monthly; content discovery is a habit, not a phase.
FAQ
- Q: Is gobuster faster than dirb or dirbuster? A: Noticeably. The Go implementation handles thousands of concurrent requests where dirb crawls single-threaded, and the memory footprint stays near zero on long runs.
- Q: Why does every path return status 200? A: A soft-404 or wildcard vhost is answering everything. Request /definitely-not-a-real-path-9482 and compare the response size - match means the server lies, switch to size-based filtering.
- Q: dns mode returns nothing but dig works? A: The resolver gobuster uses may differ from yours. Point it with --resolver 1.1.1.1 and confirm the zone actually accepts wildcard queries before blaming the wordlist.
- Q: How do I keep results out of git? A: Write with -o into a dated directory and add it to .gitignore - scan output routinely leaks internal paths, hostnames and parameter names.
RELATED ON BLACKHAT PAKISTAN
OSINT Tools for Beginners - the passive recon that tells you which domains are worth brute forcing.
Nmap Cheat Sheet 2026 - service discovery before you start guessing paths.
Bypass Cloudflare - the origin-finding workflow for when gobuster only sees the proxy.
XSS Tutorial for Beginners - take the parameters gobuster surfaces and test what they reflect.
Last edited: