How to Directory Brute Force Properly

แชร์
ฝัง
  • เผยแพร่เมื่อ 28 พ.ย. 2024

ความคิดเห็น •

  • @crusader_
    @crusader_ ปีที่แล้ว +16

    The titles are getting better Ben. Makes you wanna click the video. And the best part is you're not clickbaited.

    • @NahamSec
      @NahamSec  ปีที่แล้ว +5

      Thanks. I’m trying to walk a fine line with what I put on titles and thumbnails!

    • @AshleyEhSMR
      @AshleyEhSMR ปีที่แล้ว

      I agree, because it’s very rare I will watch a video under 20 mins and clicked when I saw it. 🎉

  • @TCMSecurityAcademy
    @TCMSecurityAcademy ปีที่แล้ว +6

    FFUF is OP and so are you.

    • @NahamSec
      @NahamSec  ปีที่แล้ว +1

      💪🏼💪🏼 thanks homie!

  • @sveneFX
    @sveneFX ปีที่แล้ว +6

    Hey Ben, thanks for sharing your knowledge! I would love to see approaches for custom wordlists, keep up the good work 👍

    • @NahamSec
      @NahamSec  ปีที่แล้ว +2

      I'll see what I can come up with :)

  • @juliusrowe9374
    @juliusrowe9374 ปีที่แล้ว +13

    Ben, super dope content! Can you do a video on how to create and maintain a decent word list and the tricks ( Do's and Don'ts) and your recommendations?

    • @NahamSec
      @NahamSec  ปีที่แล้ว +7

      I got you! Give me a few weeks.

  • @crusader_
    @crusader_ ปีที่แล้ว +1

    Loving this series

  • @rajasekharreddy7977
    @rajasekharreddy7977 ปีที่แล้ว

    Thanks man. Great video.
    Looking forward for the video for making custom wordlists.

  • @CodeAcademia00
    @CodeAcademia00 ปีที่แล้ว

    Keep going brother , that's amazing 🙏

  • @aow6813
    @aow6813 ปีที่แล้ว

    Thanks ! We love you man keep up the good work

  • @thuglife896
    @thuglife896 ปีที่แล้ว +1

    Good presentation, and explains details that other hacking channels don't 👍

  • @jokejunction415
    @jokejunction415 20 วันที่ผ่านมา

    Great content bro cant thank enough

  • @rahmat_qurishi
    @rahmat_qurishi ปีที่แล้ว +1

    Great as usual♥️

  • @abhinavkumar8052
    @abhinavkumar8052 ปีที่แล้ว +2

    exactly what I want. Thanks
    And yes make a video on how to make a custom wordlist

    • @NahamSec
      @NahamSec  ปีที่แล้ว +3

      I got you! Give me a few weeks.

    • @sourabhekka
      @sourabhekka ปีที่แล้ว

      @@NahamSec Request you to make video on " How to create/make custom wordlist based on the target?"

  • @MFoster392
    @MFoster392 ปีที่แล้ว +1

    Another great video

  • @stón_1
    @stón_1 ปีที่แล้ว +1

    feroxbuster is my favorite 🙂

  • @websuraksha1600
    @websuraksha1600 ปีที่แล้ว +1

    your content is excellent. you really do work hard for us. hey ben please make a video on how to create own wordlist.

  • @Budokid
    @Budokid 7 หลายเดือนก่อน

    I noticed in your ffuf command you don’t looked for a status of 500. Is that something you ever look for situationally? Sometimes I find that if you hit a route that is expecting certain parameters but they are missing from the request some applications will give you 500 errors

  • @shashankmudgal4581
    @shashankmudgal4581 ปีที่แล้ว

    Please make a dedicated video on how to make your own target specefic wordlist.

  • @saminbinhumayun858
    @saminbinhumayun858 8 หลายเดือนก่อน

    If there is scope given in bb program do we need to do directory bruteforcing?

  • @Hari-888
    @Hari-888 ปีที่แล้ว

    Also, you mentioned that I should do dir bruteforcing in the cloud. how exactly would I do that ? edit... Never mind, I saw on another video of yours that you mentioned running things on digitalocean.

  • @Hari-888
    @Hari-888 ปีที่แล้ว

    thank you, this was super helpful

  • @mohamedalfadile6838
    @mohamedalfadile6838 ปีที่แล้ว

    it's highly important way many thanks 😍😍

  • @nafizimtiaz9367
    @nafizimtiaz9367 ปีที่แล้ว +3

    thanks Ben. it was awesome and fun to learn things which i did in wrong. actually i came from CFT''s to web security penetration testing. A question! How long do you think i should spend on a program . and i am quite beginner in security.

    • @jaywandery9269
      @jaywandery9269 ปีที่แล้ว

      iam at the same exact level. Iam curious to understand how this is taking you so far

  • @eligoldiner
    @eligoldiner ปีที่แล้ว

    great, thanks! how would you approach a targets list of several subdomains?

  • @laurent9255
    @laurent9255 ปีที่แล้ว +3

    I found an open redirect this way . There was an endpoint like "app-login" i tried to fuzz the part after the dash "login" and found "logout". Then i fuzzed for hidden parameters on this endpoint and found "redirect" wich was vulnerable to open redirect.

    • @hackersguild8445
      @hackersguild8445 ปีที่แล้ว

      did you try for xss on that redirect parameter?

    • @laurent9255
      @laurent9255 ปีที่แล้ว

      @@hackersguild8445 Yes but i failed :(

  • @HackerJi01
    @HackerJi01 ปีที่แล้ว

    It's awesome sir ...🔥🔥

  • @eldanicarvajal
    @eldanicarvajal ปีที่แล้ว

    What do you think about feroxbuster?

  • @vladiaveryanov610
    @vladiaveryanov610 ปีที่แล้ว +2

    What is your approach if after 10 attempts you get banned by IP? Or what do you do if you generate so much traffic on the target and you need to slow down the requests per second?

    • @Pwnedby
      @Pwnedby ปีที่แล้ว

      You can lower the threads and use a proxy list

  • @brainless_bin9414
    @brainless_bin9414 ปีที่แล้ว +1

    Wfuzz and ffuf i do prefer 🔥

    • @NahamSec
      @NahamSec  ปีที่แล้ว +1

      Love ffuf!

  • @rezafadaei8388
    @rezafadaei8388 ปีที่แล้ว

    Thank you so much!
    Can you please also make a video of how to make custom world list based of the webapplication?
    What regex's are your favourite in that matter?

  • @firosiam7786
    @firosiam7786 ปีที่แล้ว +1

    Could u do a series on web hacking or smthg like that

  • @leghdaf
    @leghdaf 8 หลายเดือนก่อน

    Thanks Man ...

  • @umarfarooq9950
    @umarfarooq9950 ปีที่แล้ว

    FFUF because easy to use and automate and fast !

  • @milestips
    @milestips ปีที่แล้ว +1

    Thanks You!!!

  • @mtech1935
    @mtech1935 ปีที่แล้ว +1

    Thanks ben for the great content♥️ but the video quality is so low I have set 1080p but thw quality is very poor in case of showing any text in the video those texts are a bit blurry

    • @NahamSec
      @NahamSec  ปีที่แล้ว

      I’m not experiencing that. Everything is shot in 1080 or higher.

    • @dibens
      @dibens ปีที่แล้ว

      ​@@NahamSec The part where you show SecLists github is in low resolution. Everything else looks good.

    • @mtech1935
      @mtech1935 ปีที่แล้ว

      @nahamsec the other part is really fine but when you show some texts like you were mentioning about the seclist part it was not in good quality

  • @swoodby09
    @swoodby09 ปีที่แล้ว

    @NahamSec are you doing your recon from the cloud / vps or local?

    • @NahamSec
      @NahamSec  ปีที่แล้ว

      VPS using digital ocean. Check out the video description for some free goodies :)

  • @tyrondacreator
    @tyrondacreator 10 หลายเดือนก่อน

    Is it okay to do directory brute forcing to find assets?

    • @NahamSec
      @NahamSec  10 หลายเดือนก่อน

      Yes, but make sure you aren't sending too many requests and contextualizing your brute force.

  • @antnio773
    @antnio773 ปีที่แล้ว

    dirsearch combined with ffuf (for files as it is more easily manageable)

  • @singing_dev
    @singing_dev ปีที่แล้ว

    I use gobuster and dirbuster

  • @cadetpriyanshu6987
    @cadetpriyanshu6987 ปีที่แล้ว

    I like dirsearch ❤

  • @obfuscated65535
    @obfuscated65535 ปีที่แล้ว +3

    I like gobuster and dirsearch

    • @NahamSec
      @NahamSec  ปีที่แล้ว +1

      Dirsearch is ❤️

  • @ashleypursell9702
    @ashleypursell9702 ปีที่แล้ว

    ooft the one-app thing is a good tip thanks for this

  • @abdullahbhatti9730
    @abdullahbhatti9730 ปีที่แล้ว

    How to Brute Force in the Cloud?

    • @Hari-888
      @Hari-888 ปีที่แล้ว

      He means using a vps like digitalocean I believe

  • @fa7han748
    @fa7han748 ปีที่แล้ว

    17590 req/sec how????? :") my vps dont go to even 1000 req

  • @chiragartani
    @chiragartani ปีที่แล้ว

    Thank you! Could you please create a video about How to write a bash script for fuzzing directory on all the subdomains we got with ffuf?

    • @NahamSec
      @NahamSec  ปีที่แล้ว +2

      hmm. Maybe!

    • @Aolpha
      @Aolpha ปีที่แล้ว

      I got one working one

    • @chiragartani
      @chiragartani ปีที่แล้ว

      @@Aolpha could you share please

  • @techhacker7711
    @techhacker7711 ปีที่แล้ว

    Op bro

  • @cguzmanvisuals
    @cguzmanvisuals ปีที่แล้ว

    Personally, I prefer FFUF

  • @techofch
    @techofch ปีที่แล้ว

    with using FFUF :)

  • @M0M3NTUM33
    @M0M3NTUM33 ปีที่แล้ว +1

    Axiom... do yourself a favor... look it up

  • @Jason.1734
    @Jason.1734 ปีที่แล้ว

    It dosnt work these days servers just permanently block you

  • @DevCucr
    @DevCucr ปีที่แล้ว

    Next game pasword cracking

  • @neon_Nomad
    @neon_Nomad ปีที่แล้ว

    This is way too prescient

  • @msalih
    @msalih ปีที่แล้ว

    I just realized that we can use ffuf instead dirsearch. For Example
    domains.txt
    wordlist.txt
    extensions.txt
    ffuf -w domains.txt:D -w wordlist.txt:F -w extensions.txt:E -u D/F.E

    • @tsrisanath8441
      @tsrisanath8441 ปีที่แล้ว +1

      There is a extension flag in ffuf . It would be with -e or -x check it out with ffuf -h command

    • @msalih
      @msalih ปีที่แล้ว +1

      @@tsrisanath8441 I didnt know thanks 😊👍

  • @brainless_bin9414
    @brainless_bin9414 ปีที่แล้ว

    I'm struggling find .esp files which is pan os directory i don't know where to get it because i tried everything 🥲