Web Content Discovery & Directory Fuzzing
Exhaustive web path discovery, virtual host routing, parameter fuzzing, and CMS audit methodologies.
ffufgobusterferoxbusterwpscan
Web applications represent the largest initial foothold vector. Fuzzing endpoints and virtual host headers uncovers unindexed administration portals and legacy scripts.
1. Directory & File Fuzzing with ffuf
High-speed discovery with automatic calibration and extension recursion:
ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.html,.txt,.bak -ac -mc 200,301,302,403
2. Virtual Host (VHost) Fuzzing
Discover hidden subdomains routing on the same IP:
ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u http://{TARGET_IP} -H "Host: FUZZ.target.htb" -mc 200,301,302 -fs 1234
3. Recursive Crawling with Feroxbuster
Recursively traverse directories to depth 2:
feroxbuster -u http://{TARGET_IP}/ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-words.txt -x php,asp,aspx,jsp -d 2
4. WordPress CMS Audit
wpscan --url http://{TARGET_IP}/ --enumerate ap,at,u,cb --plugins-detection aggressive
After identifying vulnerable parameters, proceed to 03. Web Application Exploitation & Injection.
More CPTS notes
- 01. Network Discovery & Port Scanning Guide
- 03. Web Application Exploitation & Injection
- 04. Linux Privilege Escalation Master Guide
- 05. Windows Local Privilege Escalation & LOLBAS
- 06. Active Directory Attack Paths & Domain Enumeration
- 07. Kerberos Exploitation: AS-REP & Kerberoasting
- 08. Active Directory Certificate Services (AD CS) Abuse
- 09. Pivoting, Tunnels & Lateral Movement
- 10. Password Cracking & Hash Identification
- 11. Offensive File Transfers Across Restricted Networks
- 12. Interactive TTY Stabilization & Terminal Spawning
Keep these notes in your own private vault. Open CPTS notes in ZeroBox