dirs3arch – HTTP(S) directory/file brute forcer


Over Security is changing, not only graphically! Often I was urged to write articles in English, I want to start now! I ask you already apologize, because I admit to being ignorant with foreign languages. I hope you will forgive me and I’ll do my best!

Dirs3arch is a new and simple command line tool designed to brute force directories and files in websites.  I discovered thanks to my friend Alessio Dalla Piazza, is an alternative to DirBuster OWASP.

The software is written in Python so multiplatform and it is a command like application.

The feature of dirs3arch are the following:

  • Multithreaded
  • Keep alive connections
  • Support for multiple extensions (-e|–extensions asp,php)
  • Reporting (plain text, JSON)
  • Detect not found web pages when 404 not found errors are masked (.htaccess, web.config, etc).
  • Recursive brute forcing
  • HTTP(S) proxy support

The software is open source and available on GitHub, if you want to try it from the terminal type:

git clone https://github.com/maurosoria/dirs3arch.git
cd dirs3arch
python dirs3arch.py

The latest version of dirs3arch is 3, released last February and this is the changelog :

  • Ported to Python3
  • Fixed issue3
  • Fixed timeout exception
  • Other bugfixes

To download the dirs3arch you can click here, finally I anticipate that maybe you will find this tools in BackBox Linux.