Content Discovery
Discovering content on the website is a important step in the reconnaissance phase of web pentesting.
Robots.txt
http(s)://site.com/robots.txtFavicon
curl <https://static-labs.tryhackme.cloud/sites/favicon/images/favicon.ico> | md5sumSitemap.xml
http(s)://site.com/sitemap.xmlHTTP Headers
Wappalyzer extension
Wayback machine
S3 Buckets
Automated tools
ffuf
dirb
gobuster
finding files:
Find API endpoints using all HTML responses
Last updated