Content discovery: Beyond the basics


Attack strategies

Non recursive vs recursive scanning

Content discovery

Size does matter

Single target vs a list of targets

Parameter fuzzing, content discovery or directory brute forcing? HELP!


vHost brute forcing


BURP SUITE PRO: Burp suite content discovery


$ wfuzz -w wordlist/general/common.txt --hc 404 <>
$ wfuzz -w wordlist/general/common.txt --hc 404,500 <>


Full course

