aspx目录扫描字典
dirsearch的使用
-u 指定网址,例如 http://www.xxx.com/
-l 指定url字典
-e 指定网站后端开发语言,如PHP、ASP、JSP等
-w 指定字典,如果不指定,默认使用db目录下dicc.txt
-r 递归目录,例如爆破出/static/目录则继续爆破/static/下级目录,直到无法爆破出其它目录为止
-o 输出报告
-X 排除状态代码,如404、400等
-i 指定状态代码,如404、300-399等
平时用服务器来扫可以使用命令
python dirsearch.py -u http://127.0.0.1:81/ -w aspx.txt -x 404 -o logs.txt
python dirsearch.py -l url.txt -w aspx.txt -x 404 -o logs.txt
bat脚本
dirsearch.bat
@echo off
python dirsearch.py -l url.txt -w aspx.txt -x 404 -o logs.txt
字典
/admin/
/Admin/
/api/
/API/
/nacos/
/WebReport/
/geoserver/
/axis/
/editors/
/zentao/
/editor/
/uploadfiles/
/data/
/Data/
/hapood/
/zabbix/
/webroot/
/seeyon/
/wui/
/cmf/
/aspxmyadmin/
/aspxMyadmin/
/aspxMyAdmin/
/wp-admin/
/inc/
/imc/
/kubepi/
/druid/
/jeecg-boot/
/console/
/main/
/login/
/test/
/servlet/
/user/
/User/
/userportal/
/portal/
/upload/
/Upload/
/uploads/
/download/
/downloads/
/Manage/
/manage/
/manager/
/services/
/themes/
/file/
/files/
/resource/
/jeecg/
/docs/
/doc/
/..;/
/tomcat/
/bin/
/conf/
/config/
/webadmin/
/webinst/
/minio/
/sys/
/system/
/comment/
/auth/
/asserts/
/swagger/
/nuxeo/
/api-docs/
/apidocs/
/include/
/openadmin/
/frame/
/framework/
/frames/
/interface/
/Interface/
/v2/
/v3/
/v1/
/v4/
/weaver/
/home/
/public/
/Public/
/viewer/
/view/
/View/
/actions/
/masp/
/menu/
/coremail/
/account/
/Account/
/root/
/defaultroot/
/oauth/
/webGui/
/www/
/streams/
/dashboards/
/dashboard/
/html/
/web/
/tool/
/tools/
/users/
/plugins/
/messages/
/aspera/
/mobile/
/group1/
/setup/
/page/
/pages/
/Pages/
/Page/
/webservices/
/WebServices/
/document/
/rest/
/chat/
/prod-api/
/xcoa/
/workflow/
/WorkFlow/
/flow/idm/
/flow/
/iflow/
/UEditor/
/UploadFile/
/ashx/
/Ashx/
/app/
/App/
/Module/
/phone/
/Phone/
/jshERP-boot/
/Tool/
/ms/
/adm/
/member/
/sysmanage/
/common/
/Common/
/WebService/
/ioffice/
/templates/
/service/
/Service/
/server/
/Basic/
/project/
/device/
/devices/
/soap/
/center/
/SystemManager/
/base/
/cas/
/ajax/
/register/
/order/
/demo/
/logs/
/log/
/views/
/cms/
/pay/
/resources/
/pub/
/croe/
/mobile_portal/
/messager/
/theme/
/hrm/
/fr/report/
/fr/
/webtools/
/source/
/content/
/report/
/Report/
/setting/
/debug/
/handler/
/ui/
/ekp/
/shop/
/Utility/
/jsp/
/aspx/
/jmreport/
/Handler/
/plug/
/yyoa/
/audit/
/blog/
/init/
/show/
/sql/
/set/
/ibm/
/help/
/ftp/
/Extranet/
/extranet/
/application/
/applications/
/apps/
/back/
/back-up/
/backup/
/bank/
/build/
/cfg/
/cgi-bin/
/code/
/compose/
/composer/
/configuration/
/database/
/extra/
/group/
/images/
/script/
/scripts/
/js/
/css/
/ini/
/lab/
/labs/
/lib/
/libs/
/link/
/links/
/model/
/my/
/reg/
/route/
/router/
/sign/
/small/
/table/
/util/
/utils/
/vpn/
/webapp/
/wp/
/work/
/right/
/release/
/proxy/
/Proxy/
/pol/
/policy/
/poll/
/homepage/
/homework/
/host/
/hosts/
/htdocs/
/htm/
/iis/
/fun/
/edit/
/disk/
/develop/
/developement/
/development/
/default/
/con/
/client/
/bug/
/bugs/
/auto/
/new/
/news/
/start/
/fonts/
/examples/
/deploy/
/ROOT/
/install/
/rep/
/sap/
/kboard/
/CFIDE/
/eWebEditPro/
/cs/
/Fatwire/
/FutureTense/
/OpenMarket/
/Support/
/HFM/
/Security/
/Reports/
/manual/
/web-console/
/jmx-console/
/invoker/
/jbossmq-httpil/
/item/
/WEB-INF/
/rails/
/tmp/
/posts/
/assets/
/_layouts/
/NASApp/
/GXApp/
/bea_wls_cluster_internal/
/bea_wls_internal/
/bea_wls_diagnostics/
/_async/
/asyncServlet/
/wls_utc/
/GreenhouseEJB/
/GreenhouseWeb/
/Greenhouseservlet/
/TechnologySamples/
/WarehouseWeb/
/opc/
/wps/
/.env/
/.git/
/.idea/
/.inc/
/.svn/
/.vscode/
/.docker/
/.DS_Store/
/.ds_store/
/cache/
/ab/
/access/
/actuator/
/fckeditor/
/administrator/
/all/
/graphql/
/learn/
/level/
/a/
/PMA/
/pma/
/product/
/profiles/
/program/
/session/
/servlets/
/share/
/snoop/
/solr/
/sys-admin/
/sysadmin/
/ask/
/spoon/
/management/
/filemanager/
/lims/
/team/
/security/
/banner/
/iot/
/webpage/
/webjars/
/ajaxpro/
/webroot/decision/
/newoa/
/modules/
/umcenter/
/sysFile/
/fileUpload/
/notify/
/wechat/
/camera/
/copy/
/custom/
/devInfo/
/dic/
/part/
/search/
/fetch/
/Device/
/Iot/
/open/
/dept/
/message/
/userConfig/
/gpt/
/office/
/Office/
/webrtc/
/m/
/xxl-job-admin/
/xxl-job/
/admin-api/
/erp/
/crm/
/job/
/category/
/promotion/
/infra/
/mp/
/audio/
/dev/
/proc/
/video/
/mail/
/notice/
/permission/
/monitors/
/monitor/
/website/
/oa/
/wiki/
/weblogs/
/txt/
/temp/
/sqli/
/spec/
/secret/
/pprof/
/old/
/metric/
/metrics/
/local/
/kafka/
/influxdb/
/git/
/gen/
/en/admin/
/down/
/devel/
/design/
/db/
/core/
/consul/
/cloud/
/cgi/
/bbs/
/backups/
/asp/
/;/
/dist/
/aspx/
/net/
/export/
/openapi/
/weixin/
/wx/
/databases/
/update/
/settings/
/apis/
/media/
/;/admin
/;/json
/;/login
/;admin/
/;json/
/;login/
/accounts/
/activemq/
/actuators/
/admins/
/b2badmin/
/bitrix/
/cvs/
/docker/
/env/
/ext/
/includes/
/jolokia/
/jboss/
/master/
/obj/
/out/
/opt/
/owa/
/panel/
/path/
/passwd/
/password/
/passwords/
/plugin/
/remote/
/repos/
/sdist/
/Secret/
/Server/
/war/
/xml/
/zp/
/hr/
/oss/
/sso/
/app-api/
/org/
/saml/
/teams/
/datasources/
/Grafana/
/grafana/
/web-api/
/rights/
/runtime/
/runtime/log/
/common/aaaaaaaaaa
/sys/aaaaaaaa/aaaaaaa
/api/aaaaaaa/aaaaaaaaa
/system/aaaaaaaa/aaaaaaaa
/app-api/aaaaaaaa
/a/sys/aaaaaaa
/rest/aaaaaaa/aaaaaaaaa
/system/aaaaaaaaa
/menu/aaaaaaaa
/Utility/UEditor/controller.ashx?action=catchimage
/../../../../../../../../etc/passwd
/index/user/register.html
/register.html
/debug.aspx
/test.aspx
/info.aspx
/aspxinfo.aspx
/static/../../../../etc/passwd
/static/../C:\windows\win.ini
/%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd
/readme
/Workspace
/status
/WEB-INF/webapp.properties
/WEB-INF/web.xml
/compass/logon.jsp
/databasenotes.html
/nodes
/!.gitignore
/!.htaccess
/!.htpasswd
/.bash_history
/.bashrc
/.cache
/.config
/.cvs
/.cvsignore
/.forward
/.git/HEAD
/.history
/.hta
/.htaccess
/.htpasswd
/.listing
/.listings
/.mysql_history
/.passwd
/.perf
/.profile
/.rhosts
/.sh_history
/.ssh
/.subversion
/.svn
/.svn/entries
/.swf
/.web
/%EXT%
/%EXT%.bak
/%EXT%.old
/%EXT%.aspx
/%EXT%.tar
/%EXT%.tgz
/%EXT%.txt
/%EXT%.zip
/portal_inc.lua&default-language&lang=../
/.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
/.env
/.git
/.idea
/.inc
/.vscode
/.docker
/.DS_Store
/.ds_store
/.bash_aliases
/.bash_logout
/.bash_profile
/.bash_prompt
/About
/about
/login
/login.htm
/login.html
/login.jsp
/ADMIN
/Admin
/admin
/default
/default.asp
/home
/version
/config
/graphql
/install.asp
/install.aspx
/install.bak
/install.htm
/INSTALL.HTML
/INSTALL.html
/Install.html
/install.html
/install.inc
/install.log
/INSTALL.MD
/INSTALL.md
/Install.md
/install.md
/install.aspx
/install.aspx?profile=default
/install.rdf
/install.sql
/install.tpl
/INSTALL.TXT
/INSTALL.txt
/Install.txt
/install.txt
/index~
/index
/index-bak
/index-test.aspx
/index.%EXT%
/index.000
/index.001
/index.7z
/index.backup
/index.bak
/index.bz2
/index.class
/index.cs
/index.gz
/index.htm
/index.html
/index.inc
/index.java
/index.jsp
/index.old
/index.orig
/index.aspx
/index.aspx
/index.aspx-bak
/index.aspx.
/index.aspx.bak
/index.aspx/login/
/index.aspx~
/index.rar
/index.save
/index.shtml
/index.tar
/index.tar.bz2
/index.tar.gz
/index.temp
/index.tgz
/index.tmp
/index.vb
/index.xml
/index.zip
/index1.bak
/index1.htm
/index2
/index2.bak
/index2.aspx
/index3.aspx
/1
/product
/profiles
/README
/ReadMe
/Readme
/README.htm
/README.html
/ReadMe.html
/Readme.html
/readme.html
/README.MD
/README.md
/ReadMe.md
/Readme.md
/readme.md
/README.mkd
/readme.mkd
/readme.aspx
/README.TXT
/README.txt
/ReadMe.txt
/Readme.txt
/readme.txt
/Server.aspx
/Server
/server
/services
/services;.js
/service
/signin.htm
/signin.html
/signin.jsp
/signin.aspx
/snoop.jsp
/source.aspx
/web-app/plugins
/web-app/WEB-INF/classes
/web-console/Invoker
/web-console/ServerInfo.jsp
/web-console/status?full=true
/WEB-INF
/WEB-INF./
/WEB-INF./web.xml
/WEB-INF/application-client.xml
/WEB-INF/application_config.xml
/WEB-INF/applicationContext.xml
/WEB-INF/beans.xml
/WEB-INF/cas-servlet.xml
/WEB-INF/cas.properties
/WEB-INF/classes/app-config.xml
/WEB-INF/classes/application.properties
/WEB-INF/classes/application.yml
/WEB-INF/classes/applicationContext.xml
/WEB-INF/classes/cas-theme-default.properties
/WEB-INF/classes/commons-logging.properties
/WEB-INF/classes/config.properties
/WEB-INF/classes/countries.properties
/WEB-INF/classes/db.properties
/WEB-INF/classes/default-theme.properties
/WEB-INF/classes/default_views.properties
/WEB-INF/classes/demo.xml
/WEB-INF/classes/faces-config.xml
/WEB-INF/classes/fckeditor.properties
/WEB-INF/classes/hibernate.cfg.xml
/WEB-INF/classes/languages.xml
/WEB-INF/classes/log4j.properties
/WEB-INF/classes/log4j.xml
/WEB-INF/classes/logback.xml
/WEB-INF/classes/messages.properties
/WEB-INF/classes/META-INF/app-config.xml
/WEB-INF/classes/META-INF/persistence.xml
/WEB-INF/classes/mobile.xml
/WEB-INF/classes/persistence.xml
/WEB-INF/classes/protocol_views.properties
/WEB-INF/classes/resources/config.properties
/WEB-INF/classes/services.properties
/WEB-INF/classes/struts-default.vm
/WEB-INF/classes/struts.properties
/WEB-INF/classes/struts.xml
/WEB-INF/classes/theme.properties
/WEB-INF/classes/validation.properties
/WEB-INF/classes/velocity.properties
/WEB-INF/classes/web.xml
/WEB-INF/components.xml
/WEB-INF/conf/caches.dat
/WEB-INF/conf/caches.properties
/WEB-INF/conf/config.properties
/WEB-INF/conf/core.xml
/WEB-INF/conf/core_context.xml
/WEB-INF/conf/daemons.properties
/WEB-INF/conf/db.properties
/WEB-INF/conf/editors.properties
/WEB-INF/conf/jpa_context.xml
/WEB-INF/conf/jtidy.properties
/WEB-INF/conf/lutece.properties
/WEB-INF/conf/mime.types
/WEB-INF/conf/page_navigator.xml
/WEB-INF/conf/search.properties
/WEB-INF/conf/webmaster.properties
/WEB-INF/conf/wml.properties
/WEB-INF/config.xml
/WEB-INF/config/dashboard-statistics.xml
/WEB-INF/config/faces-config.xml
/WEB-INF/config/metadata.xml
/WEB-INF/config/mua-endpoints.xml
/WEB-INF/config/security.xml
/WEB-INF/config/soapConfig.xml
/WEB-INF/config/users.xml
/WEB-INF/config/web-core.xml
/WEB-INF/config/webflow-config.xml
/WEB-INF/config/webmvc-config.xml
/WEB-INF/decorators.xml
/WEB-INF/deployerConfigContext.xml
/WEB-INF/dispatcher-servlet.xml
/WEB-INF/ejb-jar.xml
/WEB-INF/faces-config.xml
/WEB-INF/geronimo-web.xml
/WEB-INF/glassfish-resources.xml
/WEB-INF/glassfish-web.xml
/WEB-INF/hibernate.cfg.xml
/WEB-INF/ias-web.xml
/WEB-INF/ibm-web-bnd.xmi
/WEB-INF/ibm-web-ext.xmi
/WEB-INF/jax-ws-catalog.xml
/WEB-INF/jboss-client.xml
/WEB-INF/jboss-deployment-structure.xml
/WEB-INF/jboss-ejb-client.xml
/WEB-INF/jboss-ejb3.xml
/WEB-INF/jboss-web.xml
/WEB-INF/jboss-webservices.xml
/WEB-INF/jetty-env.xml
/WEB-INF/jetty-web.xml
/WEB-INF/jonas-web.xml
/WEB-INF/jrun-web.xml
/WEB-INF/liferay-display.xml
/WEB-INF/liferay-layout-templates.xml
/WEB-INF/liferay-look-and-feel.xml
/WEB-INF/liferay-plugin-package.xml
/WEB-INF/liferay-portlet.xml
/WEB-INF/local-jps.properties
/WEB-INF/local.xml
/WEB-INF/logback.xml
/WEB-INF/logs/log.log
/WEB-INF/openx-config.xml
/WEB-INF/portlet-custom.xml
/WEB-INF/portlet.xml
/WEB-INF/quartz-properties.xml
/WEB-INF/remoting-servlet.xml
/WEB-INF/resin-web.xml
/WEB-INF/resources/config.properties
/WEB-INF/restlet-servlet.xml
/WEB-INF/rexip-web.xml
/WEB-INF/service.xsd
/WEB-INF/sitemesh.xml
/WEB-INF/spring-config.xml
/WEB-INF/spring-config/application-context.xml
/WEB-INF/spring-config/authorization-config.xml
/WEB-INF/spring-config/management-config.xml
/WEB-INF/spring-config/messaging-config.xml
/WEB-INF/spring-config/presentation-config.xml
/WEB-INF/spring-config/services-config.xml
/WEB-INF/spring-config/services-remote-config.xml
/WEB-INF/spring-configuration/filters.xml
/WEB-INF/spring-context.xml
/WEB-INF/spring-dispatcher-servlet.xml
/WEB-INF/spring-mvc.xml
/WEB-INF/spring-ws-servlet.xml
/WEB-INF/spring/webmvc-config.xml
/WEB-INF/springweb-servlet.xml
/WEB-INF/struts-config-ext.xml
/WEB-INF/struts-config-widgets.xml
/WEB-INF/struts-config.xml
/WEB-INF/sun-jaxws.xml
/WEB-INF/sun-web.xml
/WEB-INF/tiles-defs.xml
/WEB-INF/tjc-web.xml
/WEB-INF/trinidad-config.xml
/WEB-INF/urlrewrite.xml
/WEB-INF/validation.xml
/WEB-INF/validator-rules.xml
/WEB-INF/web-borland.xml
/WEB-INF/web-jetty.xml
/WEB-INF/web.xml.jsf
/WEB-INF/web2.xml
/WEB-INF/weblogic.xml
/WEB-INF/workflow-properties.xml
/web.7z
/web.config
/web.config.bak
/web.config.bakup
/web.config.old
/web.config.temp
/web.config.tmp
/web.config.txt
/web.config::$DATA
/web.Debug.config
/web.rar
/web.Release.config
/web.sql
/web.tar
/web.tar.bz2
/web.tar.gz
/web.tgz
/web.xml
/web.zip
/wp-config.bak
/wp-config.inc
/wp-config.old
/wp-config.aspx~
/reg.aspx
/tag.aspx
/admin.aspx
/add.aspx
/cmd.aspx
/code.aspx
/config.aspx
/conn.aspx
/connection.aspx
/count.aspx
/create.aspx
/default.aspx
/default_1.aspx
/default1.aspx
/default2.aspx
/diy.aspx
/down_addsoft.aspx
/down_picupfile.aspx
/down_picupload.aspx
/edit.aspx
/email.aspx
/err.aspx
/error.aspx
/ewebeditor.aspx
/function.aspx
/getpass.aspx
/go.aspx
/head.aspx
/img_upfile.aspx
/inc.aspx
/index1.aspx
/js.aspx
/left.aspx
/list.aspx
/logon.aspx
/main.aspx
/manage.aspx
/member_list.aspx
/more.aspx
/news.aspx
/news_list.aspx
/open.aspx
/pass.aspx
/passwd.aspx
/password.aspx
/photo.aspx
/popup.aspx
/register.aspx
/reload.aspx
/rss.aspx
/rssfree.aspx
/Saveannounce_upload.aspx
/savecomment.aspx
/savemessage.aspx
/saveup.aspx
/search.aspx
/process.aspx
/setup.aspx
/show.aspx
/shownews.aspx
/syscode.aspx
/sytle.aspx
/tb.aspx
/upfile.aspx
/upfile_flash.aspx
/upfile_soft.aspx
/Upfile_SoftPic.aspx
/upload.aspx
/UploadFace.aspx
/uploadfaceok.aspx
/user.aspx
/user_files.aspx
/user_friends.aspx
/user_help.aspx
/user_index.aspx
/user_login.aspx
/user_message.aspx
/user_messages.aspx
/user_setting.aspx
/user_subject.aspx
/user_top.aspx
/user_update.aspx
/user_upfile.aspx
/userlist.aspx
/ver.aspx
/vote.aspx
/uploads/include/dialog/select_soft_post.aspx
/upload.html
/1.aspx
/admini.aspx
/comm.aspx
/connn.aspx
/x.aspx
/bear.aspx
/help.aspx
/dos.aspx
/login.aspx
/login/login.aspx
/logon.aspx
/admin/syslogin.aspx
/book/login.aspx
/manageLogin.aspx
/Admin.aspx
/db.aspx
/setting.aspx
/admin.jsp
/view.aspx
/menu.aspx
/header.aspx
/form.aspx
/modules.aspx
/installer.aspx
/Trace.axd
/dbconf.aspx~
/license.txt
/v2/api-docs
/swagger-ui.html
/swagger
/swagger.yaml
/api-docs
/api-doc
/v3/api-docs
/api.html
/swagger-ui
/swagger/codes
/api/index.html
/api/v2/api-docs
/v2/swagger.json
/swagger-ui/html
/distv2/index.html
/swagger/index.html
/sw/swagger-ui.html
/api/swagger-ui.html
/static/swagger.json
/user/swagger-ui.html
/swagger-ui/index.html
/swagger-dubbo/api-docs
/template/swagger-ui.html
/swagger/static/index.html
/dubbo-provider/distv2/index.html
/spring-security-rest/api/swagger-ui.html
/spring-security-oauth-resource/swagger-ui.html
/swagger/v1/swagger.json
/mappings
/metrics
/beans
/configprops
/actuator/metrics
/actuator/mappings
/actuator/beans
/actuator/configprops
/actuator
/auditevents
/autoconfig
/caches
/conditions
/docs
/dump
/env
/flyway
/health
/heapdump
/httptrace
/intergrationgraph
/jolokia
/logfile
/loggers
/liquibase
/prometheus
/refresh
/scheduledtasks
/sessions
/trace
/threaddump
/actuator/auditevents
/actuator/health
/actuator/conditions
/actuator/env
/actuator/info
/actuator/loggers
/actuator/heapdump
/actuator/threaddump
/actuator/scheduledtasks
/actuator/httptrace
/actuator/jolokia
/actuator/hystrix.stream
/api/actuator
/redirect.html
/resetPwd.html
/nginx_status
/debug/pprof
/manifest.json
/swagger.json
/flag
/flags
/robots.txt
/story
/comment
/order
/review
/security
/banner
/address
/category
/sports
/ifsconsole
/monitoring
/config.js
/ReportServer
/v2/_catalog
/service.asmx
/Service.asmx
/servers.xml
/service?Wsdl
/design
/demo
/main.asp
/main.aspx
/config.properties
/Setting.xml
/trace.axd
/%2e%2e;/test
\..\..\..\..\..\..\..\..\..\etc\passwd
/accounts
/actuator/;/env
/actuator/;/configprops
/actuator/;/beans
/actuator/;/caches
/users
/services/services
/v1
/v2
/v3
/list
/search
/all
/get
/info
/init
/file
/upload
/fileupload
/download
/down
/query
/sign
/data
/rules
/doc
/getDataItem
/getItem
/api
/batch
/page
/test
/token
/products
/dataSource
/getListAll
/getPages
/user/list
/api/v1/user/list
/dataSource/list
/getDataSource
/GetUserList
/user
/rest/user
/api/user/all
/api/user
/api/user/list
/api/GetUser
/GetUser
/sys/user/list
/userlist
/api/v1/userlist
/api/userlist
/api/v1/getUserInfo
/api/v1/GetUserInfo
/api/getUserInfo
/api/GetUserInfo
/getUserInfo
/listuser
/api/v1/settings
/api/listuser
/workflow/login
/auth-ui/v1/api/user
/auth/v1/api/user
/v1/api/user
/app/api/user
/user/getAllList
/api/file
/item/list
/sys/log
/order/list
/member/list
/center/api/user
/common/system/properties
/api/properties
/properties
/api/products
/api/token
/api/token/gettoken
/user/register/init
/pageList
/orgList
/detail
/getById
/tree
/videoList
/Register
/GetUserInfo
/UserInfo
/Notify
/auth
/image/upload
/user/userlist
/ticket
/job/list
/api/config
/user/getInfo
/getInfo
/device/config
/datasources
/stats
/settings
/usersetting
/get_config
/register
/auth-redirect
/bind
/getRouters
/data/getProcess
/dict
/role
/user/profile
/menu
/menu/list
/menu/tree
/process
/sys/commont/upload