Gobuster
Tool to brute-force URIs, DNS subdomains, virtual host names, and open buckets.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse network tools →What's next with Gobuster?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Gobuster?
Gobuster is an open-source brute-force tool written in Go, designed for security professionals and penetration testers. It specializes in discovering hidden directories, files, DNS records, and virtual hosts on web servers. The tool addresses the challenge of identifying unlisted resources that may contain sensitive data or vulnerabilities. With over 14,000 stars on GitHub, it is widely used in ethical hacking to map web applications and assess their security posture. Its Apache-2.0 license allows flexible deployment, while its performance and reliability make it a staple in penetration testing workflows. Gobuster simplifies the process of uncovering potential attack surfaces by automating systematic checks against target servers.
How it works
Gobuster is a high-performance brute-force tool that automates the discovery of hidden resources on web servers. It leverages wordlists to systematically test URLs, DNS entries, and virtual hosts, helping users identify potential security gaps. Security professionals use Gobuster to map web applications, uncover misconfigured servers, and detect overlooked assets. Its primary purpose is to streamline the reconnaissance phase of penetration testing by reducing manual effort. Gobuster supports directory/file brute-forcing, DNS enumeration, and virtual host discovery. For example, it can scan for hidden directories like /admin or /backup by testing entries in a wordlist. It also identifies DNS records (A, CNAME, MX) and virtual hosts associated with a domain.
How to use it
- 1Install Gobuster via Go (go get github.com/OJ/gobuster/v3) or download binaries from GitHub. 2. Run the tool with a target URL, e.g., `gobuster dir -u https://example.com -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt`. 3. Specify scan mode (dir, dns, vhost) and optional parameters like threads or timeout. 4. Monitor output for discovered endpoints or errors. Practical tips: Use case-insensitive wordlists for accurate results, combine with tools like curl or nmap for follow-up analysis, and respect target server limits to avoid being blocked.
What it can do
- directory brute forcer
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/OJ/gobuster
- license: Apache-2.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
- Relies heavily on the quality and comprehensiveness of provided wordlists
- May generate false positives if wordlists contain irrelevant entries
- Does not support advanced HTTP methods like CSRF or SQL injection checks
- Requires stable internet connectivity for DNS-related scans
Understanding the result
Tool to brute-force URIs, DNS subdomains, virtual host names, and open buckets.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (Apache-2.0).
- Built with
- (OJ/gobuster)
- License
- Apache-2.0
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with OJ/gobuster. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- Apache-2.0
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- Apache-2.0 License
Upstream project
Frequently asked
What is Gobuster used for?
Gobuster is used to discover hidden directories, files, DNS records, and virtual hosts on web servers. It helps security professionals identify potential vulnerabilities by systematically testing URLs and network resources against predefined wordlists. This is critical in penetration testing for mapping application landscapes and uncovering misconfigurations.
How does Gobuster perform brute-force scans?
Gobuster uses parallel processing to test URLs, DNS entries, or virtual hosts by iterating through a wordlist. For directory scans, it sends HTTP requests to each entry in the list and checks for valid responses (e.g., 200 OK). DNS scans resolve subdomains against the target domain, while virtual host scans test variations of the domain name in HTTP headers. The tool filters results based on response codes and user-defined criteria.
How do I run a directory scan with Gobuster?
To scan a website's directories, run: `gobuster dir -u https://example.com -w /path/to/wordlist.txt`. Replace `https://example.com` with your target URL and `/path/to/wordlist.txt` with a valid wordlist file. Add flags like `-t 50` to set thread count or `-s 403` to filter responses with status code 403. This command will output discovered directories and files as it progresses.
How does Gobuster compare to alternatives like DirBuster or dnsenum?
Gobuster is written in Go and optimized for speed, while DirBuster (Java-based) focuses on directory brute-forcing with more advanced filtering. Dnsenum is specialized for DNS enumeration but lacks Gobuster's integrated support for virtual hosts and HTTP checks. Gobuster's modular design allows it to handle multiple scan types (dir, dns, vhost) in a single tool, making it more versatile for comprehensive reconnaissance.
What should I do if Gobuster gets blocked by the target server?
If the target blocks Gobuster, reduce the number of threads using `-t` or pause between requests with `--delay`. Use a smaller wordlist to minimize traffic. If the server enforces rate limiting, consider using tools like `gobuster` in conjunction with `curl` or `wget` for targeted checks. Always respect the target's robots.txt and terms of service to avoid legal issues.