Websites hide gold in unlinked paths: /admin, /backup.zip, /.git. Gobuster finds them with wordlists โ the recon move behind countless 'how did you find that?' moments.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
dir mode + a wordlist = hidden endpoints in seconds.
-x adds extensions. Backups of configs are instant wins.
dev/staging subdomains are frequently less protected.
One IP can host many sites โ vhost mode reveals them.
-s show codes, -b blacklist codes; tune away the noise.
| dir / dns / vhost | modes |
| -u | target URL |
| -w | wordlist |
| -x | file extensions |
| -s / -b | show / blacklist status |
| -q | quiet |
| -t | threads |
Wordlist quality = result quality: start with common.txt, SecLists raft-* for depth.
.git exposure โ check it manually; git-dumper tools can rebuild source.
ffuf is the modern faster alternative โ learn both.
301s matter: follow where they point.
Use Gobuster only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.