How to Use DirBuster: Kali Setup, Wordlists & Commands

Web Security
14 min read
How to Use DirBuster: Kali Setup, Wordlists & Commands
On this page
  1. What Is DirBuster?
  2. How to Use DirBuster in Kali Linux
    1. Check If DirBuster Is Installed
    2. Install DirBuster
    3. Launching DirBuster
  3. Understanding the DirBuster GUI
    1. Main Configuration Panel
    2. Scanning Type Selection
    3. File Extension Settings
    4. Results Display
  4. How to Use DirBuster: Step-by-Step Tutorial
    1. Step 1: Configure the Target
    2. Step 2: Select a Wordlist
    3. Step 3: Configure Extensions
    4. Step 4: Adjust Thread Count
    5. Step 5: Start the Scan
    6. Step 6: Analyze Results
    7. Step 7: Export Results
  5. DirBuster Wordlist: Choosing the Right One
    1. Default DirBuster Wordlists
    2. SecLists Collection
    3. Wordlist Strategy
  6. DirBuster Commands: The Headless Mode Catch
  7. DirBuster vs Gobuster: Which Should You Use
    1. DirBuster Advantages
    2. Gobuster Advantages
    3. Recommendation
  8. Tips for Effective Directory Enumeration
    1. Reconnaissance First
    2. Start with Focused Scans
    3. Investigate 403 Responses
    4. Watch for Custom Error Pages
    5. Consider Timing and Rate Limiting
  9. Legal and Ethical Considerations
    1. Authorized Use Cases
    2. Never Scan Without Permission
    3. Document Your Authorization
    4. Safe Practice Environments
  10. Frequently Asked Questions
    1. How do I install DirBuster on Kali Linux?
    2. What is the best wordlist for DirBuster?
    3. Is DirBuster better than Gobuster?
    4. How long does a DirBuster scan take?
    5. Why does DirBuster miss directories I know exist?
    6. Can I use DirBuster against HTTPS sites?
    7. Can I use DirBuster online without installing it?
  11. Start Practicing Directory Enumeration Today

You have found a web application during a penetration test, but the homepage reveals nothing interesting. How do you discover hidden admin panels, backup files, or forgotten endpoints? Learning how to use DirBuster is one answer. This Java-based directory enumeration tool, originally developed by OWASP, systematically probes web servers to uncover content that is not linked from the main site. For the bigger picture, see our complete penetration testing guide, and to try the technique in the browser, open our Corporate Directory Hunt lab in another tab.

This tutorial covers DirBuster end to end in 2026: installation, the GUI, wordlist choice, and the command line. One thing up front, because most tutorials skip it: DirBuster is an inactive OWASP project. The last release, 1.0-RC1, dates from 2013, and the code now lives on as the Forced Browse add-on in OWASP ZAP. It still ships with Kali and still works for its core job, but if you want a modern, actively maintained tool, Gobuster and ffuf are the faster command-line alternatives most testers reach for today (both covered later in this guide).

What Is DirBuster?

DirBuster is a multi-threaded Java application designed to brute force directories and file names on web and application servers. It was developed by the Open Web Application Security Project (OWASP), and the original code is still hosted on SourceForge (last updated in 2013). It works by making HTTP requests using entries from a wordlist to discover hidden content. The project itself is retired: OWASP folded its engine and its wordlists into ZAP's Forced Browse add-on, which is where the code gets any maintenance now.

Web applications often contain directories and files that are not linked from the main navigation. These might include:

  • Admin panels at paths like /admin or /administrator
  • Backup files such as config.bak or database.sql
  • Development files like .git folders or phpinfo.php
  • API endpoints not documented publicly
  • Old versions of files with names like index.php.old

DirBuster finds these hidden resources by systematically testing thousands of potential paths against your target. When the server responds with a status code indicating the resource exists (like 200 OK or 403 Forbidden), DirBuster flags it for your review.

In practice you drive DirBuster through its graphical interface. It ships a headless command-line switch too, but that mode has been broken for years (more on that below), so the GUI is where the real work happens. It is beginner-friendly, displaying results in real time as both a list and a tree structure that maps the discovered directory hierarchy.

Unlike some security tools that offer web-based versions, DirBuster runs locally on your machine. This gives you full control over scan parameters, wordlists, and output, but requires installation before use.

How to Use DirBuster in Kali Linux

DirBuster comes pre-installed on most penetration testing distributions. On Kali Linux, you can verify its presence or install it with a single command.

Check If DirBuster Is Installed

Open a terminal and type:

which dirbuster

If installed, this returns the path to the executable, typically /usr/bin/dirbuster.

Install DirBuster

If DirBuster is not present, install it using apt:

sudo apt update && sudo apt install dirbuster

The installation includes both the application and a collection of wordlists in /usr/share/dirbuster/wordlists/.

Launching DirBuster

You have several ways to start DirBuster:

  • From terminal: Type dirbuster and press Enter
  • From menu: Navigate to Applications > Web Application Analysis > dirbuster
  • From command line with options: dirbuster -u http://target.example

The GUI opens in a new window, ready for configuration. If you are new to Kali Linux, our guide on updating Kali Linux ensures your tools are current before testing.

After launching DirBuster, you are ready to configure your first scan. The sections below walk you through each GUI setting and explain how to run your initial directory enumeration.

💻
Practice this now: Corporate Directory Hunt - a corporate site that hides its admin panel behind an unlinked directory. Enumerate it in the browser, no Java and no setup required.

Understanding the DirBuster GUI

The DirBuster interface might look complex at first, but it is logically organized. Understanding each component helps you configure scans effectively.

Main Configuration Panel

At the top of the window, you will find the essential settings:

  • Target URL: Enter the full URL including protocol (http:// or https://) and port if non-standard
  • Work Method: Choose between GET requests (faster, default) or HEAD requests (less intrusive)
  • Number of Threads: Controls concurrent connections; default is 10
  • Go Faster checkbox: Removes politeness delay between requests

Scanning Type Selection

DirBuster offers two scanning approaches:

  • List based brute force: Uses a wordlist file; this is the most common method
  • Pure brute force: Generates character combinations; extremely slow and rarely practical

For almost all scenarios, use list-based brute force with an appropriate wordlist.

File Extension Settings

The "File extension" field lets you specify extensions to append to each wordlist entry. For example, entering php,txt,bak means each word gets tested as a directory and with each extension.

If your wordlist contains "config", DirBuster tests:

  • /config (as a directory)
  • /config.php
  • /config.txt
  • /config.bak

Results Display

The lower section shows results in two tabs:

  • Results - List View: Shows each discovery with URL, response code, and size
  • Results - Tree View: Displays the directory structure as a hierarchical tree

Both views update in real-time as DirBuster discovers content.

How to Use DirBuster: Step-by-Step Tutorial

Let us walk through a complete scan from start to finish. This tutorial assumes you have a legally authorized target.

Step 1: Configure the Target

In the "Target URL" field, enter your target address. Include the protocol and port:

http://192.168.1.100:80

For HTTPS targets:

https://target.example.com:443

The trailing slash is optional; DirBuster handles both formats.

Step 2: Select a Wordlist

Click "Browse" next to the "File with list of dirs/files" field. Navigate to the wordlists directory:

/usr/share/dirbuster/wordlists/

The dirbuster package ships two main lists plus lowercase variants:

  • directory-list-2.3-small.txt (about 87,600 entries) - Quick scans
  • directory-list-2.3-medium.txt (about 220,000 entries) - Balanced approach

Note that the 1.3-million-line "big" list is not part of the dirbuster package. It lives in SecLists as DirBuster-2007_directory-list-2.3-big.txt, so install SecLists if you need it. Start with the small or medium list and escalate only if the first pass comes up empty.

Step 3: Configure Extensions

In the "File extension" field, add extensions relevant to your target. Common choices include:

  • PHP applications: php, phps, php5, phtml
  • ASP.NET: asp, aspx, ashx, asmx
  • General web: html, htm, txt, xml, json
  • Backup files: bak, old, backup, orig, save

For a PHP target, you might enter: php,txt,bak,old

Step 4: Adjust Thread Count

The default 10 threads works for most targets. Consider these guidelines:

  • Slow servers: Reduce to 5 threads
  • Robust servers: Increase to 20-50 threads
  • Rate-limited targets: Use fewer threads to avoid blocks

Higher thread counts complete scans faster but increase the chance of detection or overwhelming the target.

Step 5: Start the Scan

Click "Start" to begin. The progress bar shows completion percentage, and the Results tabs populate with discoveries. You will see entries appear with status codes like:

  • 200 OK: Resource exists and is accessible
  • 301/302: Redirect to another location
  • 403 Forbidden: Exists but access denied
  • 404 Not Found: Does not exist (usually filtered from results)

Step 6: Analyze Results

Review discoveries in the List View. Pay special attention to:

  • 200 responses for accessible content
  • 403 responses indicating protected directories that exist
  • Unusual file names suggesting development artifacts
  • Backup extensions that might expose source code

Switch to Tree View to understand the directory hierarchy. This visualization helps you spot patterns and plan further enumeration of interesting subdirectories.

Step 7: Export Results

When the scan completes, export your findings. Go to Report > Generate Report and choose your format (HTML, XML, or plain text). This documentation is essential for professional penetration testing reports.

DirBuster Wordlist: Choosing the Right One

Your wordlist determines what DirBuster can find. A comprehensive wordlist improves discovery rates, while a targeted list reduces scan time.

Default DirBuster Wordlists

The wordlists that ship in /usr/share/dirbuster/wordlists/ cover common scenarios:

  • directory-list-2.3-small.txt: Fast scans, ~87K entries, completes in minutes
  • directory-list-2.3-medium.txt: The classic default, ~220K entries, balances speed and coverage
  • directory-list-lowercase-2.3-medium.txt: The same list, lowercased, for case-insensitive targets

The huge "big" list is a SecLists extra rather than a dirbuster file, and these lists date from 2007, so a modern crawl-based list often outperforms them.

SecLists Collection

For more options, install SecLists, the most comprehensive wordlist collection available:

sudo apt install seclists

After installation, find directory enumeration lists in /usr/share/seclists/Discovery/Web-Content/ (Kali also symlinks /usr/share/wordlists/seclists to the same place). Notable options include:

  • common.txt - Quick starting point with about 4,700 entries
  • raft-medium-directories.txt - Compiled from real website crawls, better ordered than the 2007 lists
  • DirBuster-2007_directory-list-2.3-big.txt - The exhaustive list for a slow, thorough pass

For detailed wordlist recommendations, our Gobuster wordlist guide covers selection strategies that apply equally to DirBuster.

Wordlist Strategy

Follow this approach for efficient scanning:

  1. Start with common.txt for quick wins
  2. Progress to medium lists if initial results are sparse
  3. Use large lists only for high-value targets with sufficient time
  4. Create custom lists based on target reconnaissance

DirBuster Commands: The Headless Mode Catch

DirBuster advertises a headless mode (-H) for scripting and running without a GUI. The syntax looks like this:

dirbuster -H -u http://target.example -l /path/to/wordlist.txt -e php,txt

The flags themselves are straightforward:

  • -H - Run in headless (no GUI) mode
  • -u - Target URL
  • -l - Path to wordlist file
  • -e - File extensions to test
  • -g - Use GET requests only
  • -r - Path to save the report file
  • -s - Directory to start scanning from

Here is the catch nobody mentions: headless mode is broken in the 1.0-RC1 build that Kali and everyone else ships. Launch a scan with -H and it dies immediately with a NullPointerException in Manager.start, because the code tries to update GUI panels that do not exist without a window. This is a known bug that was never fixed, which is what you get from a tool last touched in 2013. In practice, DirBuster is a GUI-only tool.

If you need real command-line directory brute-forcing, for SSH sessions, scripts, or batch runs, reach for a maintained CLI tool instead. Gobuster and ffuf were built for exactly this and finish the same wordlist far faster. Our Gobuster tutorial and ffuf guide map the workflow across.

DirBuster vs Gobuster: Which Should You Use

Modern penetration testers often ask whether to use DirBuster or its Go-based successor, Gobuster. Both tools serve similar purposes but differ in implementation and features.

DirBuster Advantages

  • GUI interface: Easier for beginners; visual tree view of results
  • Built-in reporting: Generate formatted reports directly
  • Pure brute force option: Generate character combinations (rarely useful but available)
  • Pause and resume: Stop scans and continue later

Gobuster Advantages

  • Speed: Written in Go, typically faster than Java-based DirBuster
  • Lower memory usage: More efficient for large wordlists
  • Additional modes: DNS subdomain enumeration, virtual host discovery, S3 bucket scanning
  • Active development: Regular updates and new features

Recommendation

Use DirBuster when you specifically want its GUI and tree view, or a course you are taking calls for it. Reach for Gobuster for faster scans, working command-line and scripted automation (DirBuster's is broken), or DNS and vhost enumeration. Learn its syntax from our Gobuster cheat sheet.

Tips for Effective Directory Enumeration

Getting good results from DirBuster requires more than just clicking Start. These techniques improve your discovery rate and efficiency.

Reconnaissance First

Before scanning, gather information about your target. Our Nmap cheat sheet covers the commands to fingerprint the web server and open ports first, and a Nikto scan run alongside DirBuster catches the known-risky paths a wordlist was never going to contain:

  • Identify the web server (Apache, Nginx, IIS)
  • Determine the programming language (PHP, ASP.NET, Python)
  • Note any frameworks or CMS platforms

This information guides wordlist selection and extension choices. An IIS server running ASP.NET needs different extensions than an Apache server running PHP.

Start with Focused Scans

Begin with a small wordlist and common extensions. If you find an interesting directory like /api/, run a separate scan against that path specifically:

Target URL: http://target.example/api/

This recursive approach finds deeper content without scanning the entire wordlist against every possible base path.

Investigate 403 Responses

A 403 Forbidden response means the directory exists but access is denied. These are valuable findings. The directory might:

  • Allow access from specific IPs
  • Require authentication you can bypass
  • Contain misconfigured subdirectories with looser permissions

Watch for Custom Error Pages

Some applications return 200 OK for non-existent pages with a custom "not found" message. DirBuster might report these as found. Check the response size column; legitimate pages typically have varying sizes, while error pages are uniform.

Consider Timing and Rate Limiting

Aggressive scanning triggers security controls. If you notice connection drops or increased latency:

  • Reduce thread count
  • Uncheck "Go Faster" to add delays
  • Switch from GET to HEAD requests

Patience often yields better results than speed.

DirBuster sends potentially thousands of requests to a target server. This activity is only legal when you have explicit authorization from the system owner.

Authorized Use Cases

  • Penetration testing with a signed engagement letter
  • Bug bounty programs where enumeration is in scope
  • Testing your own applications and infrastructure
  • CTF competitions and intentionally vulnerable labs
  • Educational environments designed for security practice

Never Scan Without Permission

Unauthorized scanning is illegal in most jurisdictions, regardless of intent. Even if you discover a vulnerability, accessing systems without permission can result in criminal charges. The "I was just testing" defense does not hold up in court.

Document Your Authorization

Before any penetration test, obtain written authorization that specifically includes:

  • Target IP addresses or domains
  • Testing timeframes
  • Permitted techniques (including directory enumeration)
  • Emergency contacts

Keep this documentation accessible throughout your engagement. If questioned, you can immediately prove your authorization.

Safe Practice Environments

Build your skills on intentionally vulnerable systems. Options include HackerDNA labs, OWASP WebGoat, DVWA, and VulnHub machines. These environments let you practice aggressive techniques without legal risk. Check our CTF guide for beginners for more practice platforms.

Frequently Asked Questions

How do I install DirBuster on Kali Linux?

Run sudo apt update && sudo apt install dirbuster in your terminal. On most Kali installations, DirBuster comes pre-installed. Launch it by typing dirbuster in the terminal or finding it in the applications menu under Web Application Analysis.

What is the best wordlist for DirBuster?

Start with directory-list-2.3-medium.txt for a good balance of coverage and speed. For quick scans, use common.txt from SecLists. The best choice depends on your target and time constraints.

Is DirBuster better than Gobuster?

For most work, no. DirBuster offers a GUI and a tree view, but it is an unmaintained 2013 tool and its command-line mode is broken. Gobuster is faster, actively maintained, scriptable, and supports DNS and virtual host enumeration. Use DirBuster only if you specifically want its interface; otherwise Gobuster or ffuf is the better default.

How long does a DirBuster scan take?

Scan duration depends on wordlist size, extensions, thread count, and target response time. A medium wordlist (220K entries) with 10 threads against a responsive server completes in 30-60 minutes. Large wordlists can take several hours.

Why does DirBuster miss directories I know exist?

DirBuster only finds what is in your wordlist. If a directory uses an unusual name not in your list, it will not be discovered. Try larger wordlists, add relevant extensions, or create custom wordlists based on target reconnaissance.

Can I use DirBuster against HTTPS sites?

Yes, DirBuster supports both HTTP and HTTPS. Enter the full URL with the https:// protocol in the Target URL field. The tool handles SSL/TLS connections automatically.

Can I use DirBuster online without installing it?

DirBuster is a desktop application that requires local installation. There is no official online version. Web-based directory scanners exist but lack DirBuster's customization and control. For best results, install DirBuster on Kali Linux where you can configure wordlists and scan parameters freely.

Start Practicing Directory Enumeration Today

You now know how to use DirBuster for web directory enumeration through its GUI, which is the only mode that actually works. The key points to remember: choose appropriate wordlists for your target, pay attention to all response codes including 403 errors, and always obtain proper authorization before scanning.

DirBuster still turns up hidden content that manual browsing never would, and its tree view is a genuinely nice way to see a site's structure. But it is a retired tool, so once you are comfortable with the concept, moving to Gobuster or ffuf gets you the same results faster and in a form you can script.

Ready to put your skills into practice? Explore our web attacks course for hands-on experience with directory enumeration and other web application testing techniques. The more you practice in safe environments, the more effective your real-world assessments become.

HackerDNA Team

HackerDNA Team

Written by the HackerDNA team - cybersecurity professionals building hands-on hacking labs and educational content to help you develop real-world security skills.

Meet the Team

Ready to put this into practice?

Stop reading, start hacking. Real machines, in your browser, free.

Start Hacking Free
30,000+ Hackers Real labs Free
Start Hacking Free or solve today's hack, no account needed