Terminal Dojo
Help العربية Sign inGet started

Command library / gobuster

gobuster

BashDraft — pending expert review3 practice missions

Brute-force hidden directories, files and DNS subdomains

gobuster tries a wordlist of names against a target — as URL paths (dir mode) or DNS subdomains (dns mode) — and reports which ones actually exist. The mode word (dir/dns/vhost) comes right after gobuster, then -u for the target and -w for the wordlist are both required in dir mode.

Practice gobuster

Usage

gobuster dir -u url -w wordlist [options]
Scope: Only against systems you own or are explicitly authorised to test. Directory brute-forcing is noisy — it floods the target's access log with thousands of requests.

Options and flags

Examples

Common mistakes

gobuster -u http://10.10.10.5 -w wordlist.txt gobuster dir -u http://10.10.10.5 -w wordlist.txt

gobuster needs a MODE word (dir, dns, vhost) right after the tool name, before any flags — it doesn't guess what you're enumerating.

Related commands

nmap