Understanding Web Path Scanners
- by Vince
-
in Blog
-
Hits: 3897
Kali Linux comes with a number of web path brute force utilities and when using these tools, you will find that one will work better over another when pointing at Server A versus Server B. That could be any number of reasons including defense mechanisms which is why I’d suggest changing the user agent -- something I wrote about for Nikto.
These tools are pretty simple as long as you have the correct syntax. That is -- until they don’t work which happens. In those moments, you start bouncing around between this tool, that tool, and another tool expecting a better outcome. In pentesting, there are a lot of tools and techniques to learn and the web brute force utilities are simple enough that we don’t spend time figuring out what they do behind the scenes. That said, if you take a moment and look at it from the server side, you might see why the scan is failing.