Comments (6)
dirb has been my go-to lately. It gets the job done.
from autorecon.
I have found gobuster so much faster than dirb. The only con about it that I have found is that it doesn't recursively check found directories. If I have to choose one, I would choose gobusterV3. But why not build in some logic that either checks if gobuster is installed, and reverts to running dirb if not, or else just let the user decide with a flag?
from autorecon.
Even though myself I have proposed dirb as a solution when this issue was first raised, I now believe that GoBuster is probably the way to go, especially when we talk for a tool designed to be used on CTF's. The reason is that GoBuster:
- Does not list recursively (something that saves a lot of time and is not that useful).
- Seems to be faster.
- Does not have an issue with self-signed SSL certificates (VERY IMPORTANT on CTF's).
Now of course the issue is backwards compatibility, therefore (as @cam-barts said) I believe it would be a good idea for AutoRecon to check if GoBusterV3 is installed, and if yes, to use it. Otherwise it should mention it to the user and move on using GoBusterV2. That way the average OSCP user will not be frustrated by the need to learn how the configurations work, and also it will satisfy all the users that like and use GoBuster.
from autorecon.
GoBuster seems to give me much better luck, and runs faster.
from autorecon.
+1 for gobuster
from autorecon.
Thanks for the votes. As of c46cb86, gobuster is the default directory enumeration tool, and there is also some very simple code that tries to run the correct version too.
from autorecon.
Related Issues (20)
- ModuleNotFoundError: No module named 'autorecon' HOT 4
- Tool no longer generates md reports HOT 1
- Either Slow startup or frozen with large networks HOT 2
- Too slow in ARM based kali linux HOT 1
- interface option HOT 1
- smbmap started hanging the scans HOT 4
- Issue with markdown report plugin - OffSec Proving Grounds Practice HOT 5
- Suggestion: running snmpbulkwalk to get ExtendObjects
- Thoughts on adding IPV6 checking HOT 3
- User agent configuration
- TypeError: can only concatenate str (not "list") to str HOT 2
- Is it possible to only create results folder for scans that have open ports?
- Where is the --profile option now? HOT 6
- Trouble getting heartbeat to work HOT 2
- dirbuster scans often never finish HOT 16
- smbmap hanging every scan i run HOT 2
- SyntaxWarning: Invalid Escape Sequence HOT 1
- dirbuster (feroxbuster) scans hang, doesn't generate any network traffic HOT 2
- Enter key temporarily sent to feroxbuster scanner HOT 2
- Error: There are no valid PortScan plugins in the plugins directory "/root/.local/share/AutoRecon/plugins" HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from autorecon.