Command library / gobuster
gobuster
Brute-force hidden directories, files and DNS subdomains
gobuster tries a wordlist of names against a target — as URL paths (dir mode) or DNS subdomains (dns mode) — and reports which ones actually exist. The mode word (dir/dns/vhost) comes right after gobuster, then -u for the target and -w for the wordlist are both required in dir mode.
Practice gobusterUsage
Options and flags
modedir (web paths), dns (subdomains) or vhost (virtual hosts)
-u, --urlURLthe target URL (dir mode) or domain (dns mode)
-w, --wordlistFILEpath to the wordlist file
-x, --extensionsLISTfile extensions to also try, comma-separated (e.g. php,txt,bak)
-t, --threadsNnumber of concurrent threads (default 10)
Examples
gobuster dir -u http://10.10.10.5 -w /usr/share/wordlists/dirb/common.txtTry every word in the common wordlist as a path on the target site.
gobuster dir -u http://10.10.10.5 -w wordlist.txt -x php,txt,bakAlso try each word with .php, .txt and .bak appended — catches forgotten backup files.
gobuster dir -u http://10.10.10.5 -w wordlist.txt -t 50Speed the scan up with 50 threads instead of the default 10.
Common mistakes
gobuster needs a MODE word (dir, dns, vhost) right after the tool name, before any flags — it doesn't guess what you're enumerating.