Dirb — Инструмент для подбора URL-адресов

Что это

DIRB — сканер веб-контента. Он ищет существующие (и/или скрытые) веб-объекты. По сути, он работает путем запуска атаки на веб-сервер на основе словаря и анализа ответов.

Оригинал описания (EN)

DIRB is a Web Content Scanner. It looks for existing (and/or hidden) Web Objects. It basically works by launching a dictionary based attack against a web server and analyzing the responses.

Пример использования

root@kali:~# man dirb
DIRB(1)                     General Commands Manual                     DIRB(1)

NAME dirb - Web Content Scanner

SYNOPSIS dirb <url_base> <url_base> [<wordlist_file(s)>] [options]

DESCRIPTION DIRB IS a Web Content Scanner. It looks for existing (and/or hidden) Web Objects. It basically works by launching a dictionary basesd attack against a web server and analizing the response.

OPTIONS -a <agent_string> Specify your custom USER_AGENT. (Default is: "Mozilla/4.0 (compat- ible; MSIE 6.0; Windows NT 5.1)")

 -b     Don't squash or merge sequences of /../ or /./ in the given URL.

 -c &lt;cookie_string>
        Set a cookie for the HTTP request.

 -E &lt;certificate>
        Use the specified client certificate file.

 -f     Fine tunning of NOT_FOUND (404) detection.

 -H &lt;header_string>
        Add a custom header to the HTTP request.

 -i     Use case-insensitive Search.

 -l     Print "Location" header when found.

 -N &lt;nf_code>
        Ignore responses with this HTTP code.

 -o &lt;output_file>
        Save output to disk.

 -p &lt;proxy[:port]>
        Use this proxy. (Default port is 1080)

 -P &lt;proxy_username:proxy_password>
        Proxy Authentication.

 -r     Don't Search Recursively.

 -R     Interactive Recursion.  (Ask in which directories you want to scan)

 -S     Silent Mode. Don't show tested words. (For dumb terminals)

 -t     Don't force an ending '/' on URLs.

 -u &lt;username:password>
        Username and password to use.

 -v     Show Also Not Existent Pages.

 -w     Don't Stop on WARNING messages.

 -x &lt;extensions_file>
        Amplify search with the extensions o</code></pre>

Пакеты и установка

dirb

Инструмент для подбора URL-адресов
Установка: sudo apt install dirb

Официальная документация

https://www.kali.org/tools/dirb/

Комментарии