You have found a web application during a penetration test, but the homepage reveals nothing interesting. How do you discover hidden admin panels, backup files, or forgotten endpoints? Learning how to use DirBuster is one answer. This Java-based directory enumeration tool, originally developed by OWASP, systematically probes web servers to uncover content that is not linked from the main site. For the bigger picture, see our complete penetration testing guide, and to try the technique in the browser, open our Corporate Directory Hunt lab in another tab.
This tutorial covers DirBuster end to end in 2026: installation, the GUI, wordlist choice, and the command line. One thing up front, because most tutorials skip it: DirBuster is an inactive OWASP project. The last release, 1.0-RC1, dates from 2013, and the code now lives on as the Forced Browse add-on in OWASP ZAP. It still ships with Kali and still works for its core job, but if you want a modern, actively maintained tool, Gobuster and ffuf are the faster command-line alternatives most testers reach for today (both covered later in this guide).
What Is DirBuster?
DirBuster is a multi-threaded Java application designed to brute force directories and file names on web and application servers. It was developed by the Open Web Application Security Project (OWASP), and the original code is still hosted on SourceForge (last updated in 2013). It works by making HTTP requests using entries from a wordlist to discover hidden content. The project itself is retired: OWASP folded its engine and its wordlists into ZAP's Forced Browse add-on, which is where the code gets any maintenance now.
Web applications often contain directories and files that are not linked from the main navigation. These might include:
- Admin panels at paths like
/adminor/administrator - Backup files such as
config.bakordatabase.sql - Development files like
.gitfolders orphpinfo.php - API endpoints not documented publicly
- Old versions of files with names like
index.php.old
DirBuster finds these hidden resources by systematically testing thousands of potential paths against your target. When the server responds with a status code indicating the resource exists (like 200 OK or 403 Forbidden), DirBuster flags it for your review.
In practice you drive DirBuster through its graphical interface. It ships a headless command-line switch too, but that mode has been broken for years (more on that below), so the GUI is where the real work happens. It is beginner-friendly, displaying results in real time as both a list and a tree structure that maps the discovered directory hierarchy.
Unlike some security tools that offer web-based versions, DirBuster runs locally on your machine. This gives you full control over scan parameters, wordlists, and output, but requires installation before use.
How to Use DirBuster in Kali Linux
DirBuster comes pre-installed on most penetration testing distributions. On Kali Linux, you can verify its presence or install it with a single command.
Check If DirBuster Is Installed
Open a terminal and type:
which dirbuster
If installed, this returns the path to the executable, typically /usr/bin/dirbuster.
Install DirBuster
If DirBuster is not present, install it using apt:
sudo apt update && sudo apt install dirbuster
The installation includes both the application and a collection of wordlists in /usr/share/dirbuster/wordlists/.
Launching DirBuster
You have several ways to start DirBuster:
- From terminal: Type
dirbusterand press Enter - From menu: Navigate to Applications > Web Application Analysis > dirbuster
- From command line with options:
dirbuster -u http://target.example
The GUI opens in a new window, ready for configuration. If you are new to Kali Linux, our guide on updating Kali Linux ensures your tools are current before testing.
After launching DirBuster, you are ready to configure your first scan. The sections below walk you through each GUI setting and explain how to run your initial directory enumeration.
Understanding the DirBuster GUI
The DirBuster interface might look complex at first, but it is logically organized. Understanding each component helps you configure scans effectively.
Main Configuration Panel
At the top of the window, you will find the essential settings:
- Target URL: Enter the full URL including protocol (http:// or https://) and port if non-standard
- Work Method: Choose between GET requests (faster, default) or HEAD requests (less intrusive)
- Number of Threads: Controls concurrent connections; default is 10
- Go Faster checkbox: Removes politeness delay between requests
Scanning Type Selection
DirBuster offers two scanning approaches:
- List based brute force: Uses a wordlist file; this is the most common method
- Pure brute force: Generates character combinations; extremely slow and rarely practical
For almost all scenarios, use list-based brute force with an appropriate wordlist.
File Extension Settings
The "File extension" field lets you specify extensions to append to each wordlist entry. For example, entering php,txt,bak means each word gets tested as a directory and with each extension.
If your wordlist contains "config", DirBuster tests:
/config(as a directory)/config.php/config.txt/config.bak
Results Display
The lower section shows results in two tabs:
- Results - List View: Shows each discovery with URL, response code, and size
- Results - Tree View: Displays the directory structure as a hierarchical tree
Both views update in real-time as DirBuster discovers content.
How to Use DirBuster: Step-by-Step Tutorial
Let us walk through a complete scan from start to finish. This tutorial assumes you have a legally authorized target.
Step 1: Configure the Target
In the "Target URL" field, enter your target address. Include the protocol and port:
http://192.168.1.100:80
For HTTPS targets:
https://target.example.com:443
The trailing slash is optional; DirBuster handles both formats.
Step 2: Select a Wordlist
Click "Browse" next to the "File with list of dirs/files" field. Navigate to the wordlists directory:
/usr/share/dirbuster/wordlists/
The dirbuster package ships two main lists plus lowercase variants:
directory-list-2.3-small.txt(about 87,600 entries) - Quick scansdirectory-list-2.3-medium.txt(about 220,000 entries) - Balanced approach
Note that the 1.3-million-line "big" list is not part of the dirbuster package. It lives in SecLists as DirBuster-2007_directory-list-2.3-big.txt, so install SecLists if you need it. Start with the small or medium list and escalate only if the first pass comes up empty.
Step 3: Configure Extensions
In the "File extension" field, add extensions relevant to your target. Common choices include:
- PHP applications: php, phps, php5, phtml
- ASP.NET: asp, aspx, ashx, asmx
- General web: html, htm, txt, xml, json
- Backup files: bak, old, backup, orig, save
For a PHP target, you might enter: php,txt,bak,old
Step 4: Adjust Thread Count
The default 10 threads works for most targets. Consider these guidelines:
- Slow servers: Reduce to 5 threads
- Robust servers: Increase to 20-50 threads
- Rate-limited targets: Use fewer threads to avoid blocks
Higher thread counts complete scans faster but increase the chance of detection or overwhelming the target.
Step 5: Start the Scan
Click "Start" to begin. The progress bar shows completion percentage, and the Results tabs populate with discoveries. You will see entries appear with status codes like:
- 200 OK: Resource exists and is accessible
- 301/302: Redirect to another location
- 403 Forbidden: Exists but access denied
- 404 Not Found: Does not exist (usually filtered from results)
Step 6: Analyze Results
Review discoveries in the List View. Pay special attention to:
- 200 responses for accessible content
- 403 responses indicating protected directories that exist
- Unusual file names suggesting development artifacts
- Backup extensions that might expose source code
Switch to Tree View to understand the directory hierarchy. This visualization helps you spot patterns and plan further enumeration of interesting subdirectories.
Step 7: Export Results
When the scan completes, export your findings. Go to Report > Generate Report and choose your format (HTML, XML, or plain text). This documentation is essential for professional penetration testing reports.
DirBuster Wordlist: Choosing the Right One
Your wordlist determines what DirBuster can find. A comprehensive wordlist improves discovery rates, while a targeted list reduces scan time.
Default DirBuster Wordlists
The wordlists that ship in /usr/share/dirbuster/wordlists/ cover common scenarios:
- directory-list-2.3-small.txt: Fast scans, ~87K entries, completes in minutes
- directory-list-2.3-medium.txt: The classic default, ~220K entries, balances speed and coverage
- directory-list-lowercase-2.3-medium.txt: The same list, lowercased, for case-insensitive targets
The huge "big" list is a SecLists extra rather than a dirbuster file, and these lists date from 2007, so a modern crawl-based list often outperforms them.
SecLists Collection
For more options, install SecLists, the most comprehensive wordlist collection available:
sudo apt install seclists
After installation, find directory enumeration lists in /usr/share/seclists/Discovery/Web-Content/ (Kali also symlinks /usr/share/wordlists/seclists to the same place). Notable options include:
common.txt- Quick starting point with about 4,700 entriesraft-medium-directories.txt- Compiled from real website crawls, better ordered than the 2007 listsDirBuster-2007_directory-list-2.3-big.txt- The exhaustive list for a slow, thorough pass
For detailed wordlist recommendations, our Gobuster wordlist guide covers selection strategies that apply equally to DirBuster.
Wordlist Strategy
Follow this approach for efficient scanning:
- Start with common.txt for quick wins
- Progress to medium lists if initial results are sparse
- Use large lists only for high-value targets with sufficient time
- Create custom lists based on target reconnaissance
DirBuster Commands: The Headless Mode Catch
DirBuster advertises a headless mode (-H) for scripting and running without a GUI. The syntax looks like this:
dirbuster -H -u http://target.example -l /path/to/wordlist.txt -e php,txt
The flags themselves are straightforward:
-H- Run in headless (no GUI) mode-u- Target URL-l- Path to wordlist file-e- File extensions to test-g- Use GET requests only-r- Path to save the report file-s- Directory to start scanning from
Here is the catch nobody mentions: headless mode is broken in the 1.0-RC1 build that Kali and everyone else ships. Launch a scan with -H and it dies immediately with a NullPointerException in Manager.start, because the code tries to update GUI panels that do not exist without a window. This is a known bug that was never fixed, which is what you get from a tool last touched in 2013. In practice, DirBuster is a GUI-only tool.
If you need real command-line directory brute-forcing, for SSH sessions, scripts, or batch runs, reach for a maintained CLI tool instead. Gobuster and ffuf were built for exactly this and finish the same wordlist far faster. Our Gobuster tutorial and ffuf guide map the workflow across.
DirBuster vs Gobuster: Which Should You Use
Modern penetration testers often ask whether to use DirBuster or its Go-based successor, Gobuster. Both tools serve similar purposes but differ in implementation and features.
DirBuster Advantages
- GUI interface: Easier for beginners; visual tree view of results
- Built-in reporting: Generate formatted reports directly
- Pure brute force option: Generate character combinations (rarely useful but available)
- Pause and resume: Stop scans and continue later
Gobuster Advantages
- Speed: Written in Go, typically faster than Java-based DirBuster
- Lower memory usage: More efficient for large wordlists
- Additional modes: DNS subdomain enumeration, virtual host discovery, S3 bucket scanning
- Active development: Regular updates and new features
Recommendation
Use DirBuster when you specifically want its GUI and tree view, or a course you are taking calls for it. Reach for Gobuster for faster scans, working command-line and scripted automation (DirBuster's is broken), or DNS and vhost enumeration. Learn its syntax from our Gobuster cheat sheet.
Tips for Effective Directory Enumeration
Getting good results from DirBuster requires more than just clicking Start. These techniques improve your discovery rate and efficiency.
Reconnaissance First
Before scanning, gather information about your target. Our Nmap cheat sheet covers the commands to fingerprint the web server and open ports first, and a Nikto scan run alongside DirBuster catches the known-risky paths a wordlist was never going to contain:
- Identify the web server (Apache, Nginx, IIS)
- Determine the programming language (PHP, ASP.NET, Python)
- Note any frameworks or CMS platforms
This information guides wordlist selection and extension choices. An IIS server running ASP.NET needs different extensions than an Apache server running PHP.
Start with Focused Scans
Begin with a small wordlist and common extensions. If you find an interesting directory like /api/, run a separate scan against that path specifically:
Target URL: http://target.example/api/
This recursive approach finds deeper content without scanning the entire wordlist against every possible base path.
Investigate 403 Responses
A 403 Forbidden response means the directory exists but access is denied. These are valuable findings. The directory might:
- Allow access from specific IPs
- Require authentication you can bypass
- Contain misconfigured subdirectories with looser permissions
Watch for Custom Error Pages
Some applications return 200 OK for non-existent pages with a custom "not found" message. DirBuster might report these as found. Check the response size column; legitimate pages typically have varying sizes, while error pages are uniform.
Consider Timing and Rate Limiting
Aggressive scanning triggers security controls. If you notice connection drops or increased latency:
- Reduce thread count
- Uncheck "Go Faster" to add delays
- Switch from GET to HEAD requests
Patience often yields better results than speed.
Legal and Ethical Considerations
DirBuster sends potentially thousands of requests to a target server. This activity is only legal when you have explicit authorization from the system owner.
Authorized Use Cases
- Penetration testing with a signed engagement letter
- Bug bounty programs where enumeration is in scope
- Testing your own applications and infrastructure
- CTF competitions and intentionally vulnerable labs
- Educational environments designed for security practice
Never Scan Without Permission
Unauthorized scanning is illegal in most jurisdictions, regardless of intent. Even if you discover a vulnerability, accessing systems without permission can result in criminal charges. The "I was just testing" defense does not hold up in court.
Document Your Authorization
Before any penetration test, obtain written authorization that specifically includes:
- Target IP addresses or domains
- Testing timeframes
- Permitted techniques (including directory enumeration)
- Emergency contacts
Keep this documentation accessible throughout your engagement. If questioned, you can immediately prove your authorization.
Safe Practice Environments
Build your skills on intentionally vulnerable systems. Options include HackerDNA labs, OWASP WebGoat, DVWA, and VulnHub machines. These environments let you practice aggressive techniques without legal risk. Check our CTF guide for beginners for more practice platforms.
Frequently Asked Questions
How do I install DirBuster on Kali Linux?
Run sudo apt update && sudo apt install dirbuster in your terminal. On most Kali installations, DirBuster comes pre-installed. Launch it by typing dirbuster in the terminal or finding it in the applications menu under Web Application Analysis.
What is the best wordlist for DirBuster?
Start with directory-list-2.3-medium.txt for a good balance of coverage and speed. For quick scans, use common.txt from SecLists. The best choice depends on your target and time constraints.
Is DirBuster better than Gobuster?
For most work, no. DirBuster offers a GUI and a tree view, but it is an unmaintained 2013 tool and its command-line mode is broken. Gobuster is faster, actively maintained, scriptable, and supports DNS and virtual host enumeration. Use DirBuster only if you specifically want its interface; otherwise Gobuster or ffuf is the better default.
How long does a DirBuster scan take?
Scan duration depends on wordlist size, extensions, thread count, and target response time. A medium wordlist (220K entries) with 10 threads against a responsive server completes in 30-60 minutes. Large wordlists can take several hours.
Why does DirBuster miss directories I know exist?
DirBuster only finds what is in your wordlist. If a directory uses an unusual name not in your list, it will not be discovered. Try larger wordlists, add relevant extensions, or create custom wordlists based on target reconnaissance.
Can I use DirBuster against HTTPS sites?
Yes, DirBuster supports both HTTP and HTTPS. Enter the full URL with the https:// protocol in the Target URL field. The tool handles SSL/TLS connections automatically.
Can I use DirBuster online without installing it?
DirBuster is a desktop application that requires local installation. There is no official online version. Web-based directory scanners exist but lack DirBuster's customization and control. For best results, install DirBuster on Kali Linux where you can configure wordlists and scan parameters freely.
Start Practicing Directory Enumeration Today
You now know how to use DirBuster for web directory enumeration through its GUI, which is the only mode that actually works. The key points to remember: choose appropriate wordlists for your target, pay attention to all response codes including 403 errors, and always obtain proper authorization before scanning.
DirBuster still turns up hidden content that manual browsing never would, and its tree view is a genuinely nice way to see a site's structure. But it is a retired tool, so once you are comfortable with the concept, moving to Gobuster or ffuf gets you the same results faster and in a form you can script.
Ready to put your skills into practice? Explore our web attacks course for hands-on experience with directory enumeration and other web application testing techniques. The more you practice in safe environments, the more effective your real-world assessments become.
Part of the Penetration Testing series
Related articles: