ZeroBox

Web Content Discovery & Directory Fuzzing

Exhaustive web path discovery, virtual host routing, parameter fuzzing, and CMS audit methodologies.

ffufgobusterferoxbusterwpscan

Web applications represent the largest initial foothold vector. Fuzzing endpoints and virtual host headers uncovers unindexed administration portals and legacy scripts.

1. Directory & File Fuzzing with ffuf

High-speed discovery with automatic calibration and extension recursion:

ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.html,.txt,.bak -ac -mc 200,301,302,403

2. Virtual Host (VHost) Fuzzing

Discover hidden subdomains routing on the same IP:

ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u http://{TARGET_IP} -H "Host: FUZZ.target.htb" -mc 200,301,302 -fs 1234

3. Recursive Crawling with Feroxbuster

Recursively traverse directories to depth 2:

feroxbuster -u http://{TARGET_IP}/ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-words.txt -x php,asp,aspx,jsp -d 2

4. WordPress CMS Audit

wpscan --url http://{TARGET_IP}/ --enumerate ap,at,u,cb --plugins-detection aggressive

After identifying vulnerable parameters, proceed to 03. Web Application Exploitation & Injection.

More CPTS notes

Keep these notes in your own private vault. Open CPTS notes in ZeroBox