Here I try to look for ‘specific-file.txt’ via LFI in uknown dir. The disadvantage of ffuf here is it requires FUZZ keyword to be at the end of url like:
I’m looking for a tool which will add another layer of subdir to search for.
For example, if it won’t find the desired file in any of dir name given in wordlist, it’ll try to search recursively.
This question is related to specific machine on HTB which I already pwned.
Dirseach also will try the word without extension (it have a param to add ‘/’ when no extension given).
If it founds any directory with that, when finish checking the wordlist against root (/) of the host, it will take any hit (without extension) and starts again from there.
In the output you can see, after trying all wordlist permutations in root level one hit it’s found: v2.
As it is a folder, it will iterate again the whole wordlist + extensions from that folder (with every folder it founds) /v2/.
Another hit found inside the folder /v2/_catalog.
Dirsearch allows to specify how many recursion levels you want to check, in the example i only want 1 level deep, that’s why it din’t continue after found _catalog even if it hasn’t any extension.
But pay attention if you specify some extensions with -e. Indeed, another important parameter is -f, it indicates to try every word of the wordlist with the extensions specified. Without it won’t do it.
For your needs, the parameter is -r, as indicated by @rulzgz and you can indicates the level indeed, like this -r 2.
Ofthen I use lowercase too -l and the threads limit -t 50.
Thanks for replies. Anyways, wfuzz is not able to do what I want since it requires (in recursive mode) to have FUZZ keyword at the and of URL. That’s not what I’m looking for.
I tried dirsearch but it also won’t help me, because of trailing /.
As @rulzgz wrote, if I’d search for dirs with wordlist recursively, dirsearch will append / to the end of path. While this is fine for dirs, it won’t work for files.
Example:
@choupit0 - thanks, but ur command didn’t work for me either :<
Maybe I’m trying to knock out open door but how else I’d find that dir in Tabby machine?
You know what dir I mean rigth? Was the only way to find it educated guess? Or was it possible with tool? Which one?