1. 精准扫描策略
- 自定义字典组合
# 合并多个字典文件 type db\common.txt db\php.txt > custom_dict.txt # 使用自定义字典扫描 python dirsearch.py -u https://example.com -w "db\common.txt,db\php.txt" |
- 扩展名智能替换
# 将字典中所有.php替换为.aspx python dirsearch.py -u https://example.com -w db\php.txt -e aspx --force-extensions |
- 递归扫描深度控制
# 递归扫描2层深度 python dirsearch.py -u https://example.com -r -R2 |
2. 高级请求配置
- 携带Cookie扫描
# 命令行直接指定Cookie python dirsearch.py -u https://example.com --cookie "session_id=xxx; user=admin" # 从文件加载Cookie python dirsearch.py -u https://example.com --headers-file cookies.txt |
- 自定义请求头
python dirsearch.py -u https://example.com -H "Referer: https://google.com" -H "X-Forwarded-For: 192.168.1.1" |
- POST请求扫描
python dirsearch.py -u https://example.com/api/auth \ |
3. 结果分析与处理
- 结果过滤与导出:只保留有效结果并保存
# 仅保留200/302状态码结果,保存为JSON格式 python dirsearch.py -u https://example.com \ |
- 批量扫描目标:从文件加载多个目标
python3 dirsearch.py \ |
- 静默模式输出:仅显示关键结果,减少日志干扰
python dirsearch.py -u https://example.com -q |