WebApp Sec mailing list archives

Re: enumerate a directory structure on web server


From: Ramon Pinuaga Cascales <rpinuaga () s21sec com>
Date: Sun, 29 Aug 2004 13:33:27 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: MD5

Hi Serg,

SB> Is there a way to somehow enumerate a directory structure on a remote
SB> webserver? Brute force springs to mind but thats mathematically
SB> impossible, to go through all combinations, etc.

You can try DIRB (originally directory bruteforcer)

http://www.t0s.org/dirb.php

It works by launching a dictionary attack against a web directory an
analizing the responses.

- --
Saludos,
 Ramon                            mailto:rpinuaga () s21sec com

-----BEGIN PGP SIGNATURE-----
Version: 2.6

iQEVAwUAQTG/CpCN2MkDASy5AQGE1Qf+M6pBy6djUg52l56d4t5EHXXMX2viSOoj
yMfqiJMYQdYteRFmudhZ9XB0YhzSSU5VpgbmlbXK5eT7eOzhs7k1o59IB9gb/f3N
hkXLcqPpsMlfCsWAJCXGeayoXbnQxLPgYTG6ndMZ/QGRLOJffQEWCoCXA/2aj+Bf
uXK4ZsSwG6vzgDxEXH2JbKWwVgOd2HWbIjKbM6XcppNKXmIss4aVidy7WSTGUssQ
aXnZO9reYWKNball0UVPRSdMajOpOAk+MwLcNrfY+Y4QKNn40MN+DYfuCMVrDurG
nkSNl/iHGTVzV6oXoj3U1PJE89qd582PHBW//NJ3AIEiAxo8iC1ghw==
=b8OK
-----END PGP SIGNATURE-----



Current thread: