**En SecLists-master/Discovery/Web-Content está directory-list-2.3-medium.txt**\\ **Mirar el content lenght que devuelve de una página que no exista**\\ curl -i https://gov.karelia.ru/noexistes | grep content-leng % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0content-length: 81494 100 81494 100 81494 0 0 68674 0 0:00:01 0:00:01 --:--:-- 68655 **Si ponemos páginas que existen devolverá content-length bajos**\\ curl -i https://gov.karelia.ru/gov | grep content-leng % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 298 100 298 0 0 565 0 --:--:-- --:--:-- --:--:-- 566 content-length: 298 wget -c https://github.com/danielmiessler/SecLists/archive/master.zip -O SecList.zip && unzip SecList.zip && rm -f SecList.zip -fw: Fuerza mostrar resultados aunque la respuesta sea sospechosa o genérica, filtra por longitud y excluye las que tengan esa longitud o estén en el rango de longitud especificada, si la página no existe dará content lengths altos por eso ponemos un rango entre 60000 y 90000.\\ -ac: autocalibración para filtrar wildcards\\ ffuf -u https://gov.karelia.ru/FUZZ -w directory-list-2.3-medium.txt -ac -fw 60000-90894 /'___\ /'___\ /'___\ /\ \__/ /\ \__/ __ __ /\ \__/ \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\ \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/ \ \_\ \ \_\ \ \____/ \ \_\ \/_/ \/_/ \/___/ \/_/ v1.1.0 ________________________________________________ :: Method : GET :: URL : https://gov.karelia.ru/FUZZ :: Wordlist : FUZZ: directory-list-2.3-medium.txt :: Follow redirects : false :: Calibration : true :: Timeout : 10 :: Threads : 40 :: Matcher : Response status: 200,204,301,302,307,401,403 :: Filter : Response size: 1131 :: Filter : Response lines: 24 :: Filter : Response words: 54 ________________________________________________ images [Status: 301, Size: 301, Words: 19, Lines: 10] search [Status: 301, Size: 301, Words: 19, Lines: 10] news [Status: 301, Size: 299, Words: 19, Lines: 10] # [Status: 200, Size: 126427, Words: 32514, Lines: 1589] # Copyright 2007 James Fisher [Status: 200, Size: 126419, Words: 32514, Lines: 1589] # or send a letter to Creative Commons, 171 Second Street, [Status: 200, Size: 126427, Words: 32514, Lines: 1589] # This work is licensed under the Creative Commons [Status: 200, Size: 126427, Words: 32514, Lines: 1589] # license, visit http://creativecommons.org/licenses/by-sa/3.0/ [Status: 200, Size: 126427, Words: 32514, Lines: 1589] # on at least 2 different hosts [Status: 200, Size: 126419, Words: 32514, Lines: 1589] # Suite 300, San Francisco, California, 94105, USA. [Status: 200, Size: 126419, Words: 32514, Lines: 1589] # [Status: 200, Size: 126427, Words: 32514, Lines: 1589] # [Status: 200, Size: 126419, Words: 32514, Lines: 1589] # Priority ordered case-sensitive list, where entries were found [Status: 200, Size: 126427, Words: 32514, Lines: 1589] # directory-list-2.3-medium.txt [Status: 200, Size: 126427, Words: 32514, Lines: 1589] banners [Status: 301, Size: 302, Words: 19, Lines: 10] [Status: 200, Size: 126427, Words: 32514, Lines: 1589] # Attribution-Share Alike 3.0 License. To view a copy of this [Status: 200, Size: 126427, Words: 32514, Lines: 1589] # [Status: 200, Size: 126419, Words: 32514, Lines: 1589] pub [Status: 301, Size: 298, Words: 19, Lines: 10] upload [Status: 301, Size: 162, Words: 5, Lines: 8] local [Status: 301, Size: 300, Words: 19, Lines: 10] personal [Status: 301, Size: 303, Words: 19, Lines: 10] poll [Status: 301, Size: 299, Words: 19, Lines: 10] information [Status: 301, Size: 306, Words: 19, Lines: 10] test [Status: 301, Size: 299, Words: 19, Lines: 10] includes [Status: 301, Size: 303, Words: 19, Lines: 10] announcements [Status: 301, Size: 308, Words: 19, Lines: 10] polls [Status: 301, Size: 300, Words: 19, Lines: 10] vote [Status: 301, Size: 299, Words: 19, Lines: 10] whois [Status: 301, Size: 300, Words: 19, Lines: 10] lang [Status: 301, Size: 299, Words: 19, Lines: 10] legislation [Status: 301, Size: 306, Words: 19, Lines: 10] interview [Status: 301, Size: 304, Words: 19, Lines: 10] question [Status: 301, Size: 303, Words: 19, Lines: 10] power [Status: 301, Size: 300, Words: 19, Lines: 10] gov [Status: 301, Size: 298, Words: 19, Lines: 10] control [Status: 301, Size: 302, Words: 19, Lines: 10] structure [Status: 301, Size: 304, Words: 19, Lines: 10] answer [Status: 301, Size: 301, Words: 19, Lines: 10] lp [Status: 301, Size: 297, Words: 19, Lines: 10] bitrix [Status: 301, Size: 301, Words: 19, Lines: 10] association [Status: 301, Size: 306, Words: 19, Lines: 10] income [Status: 301, Size: 301, Words: 19, Lines: 10] actual [Status: 301, Size: 301, Words: 19, Lines: 10] appeal [Status: 301, Size: 301, Words: 19, Lines: 10] karelia [Status: 301, Size: 302, Words: 19, Lines: 10] [Status: 200, Size: 126419, Words: 32514, Lines: 1589] antiterror [Status: 301, Size: 305, Words: 19, Lines: 10] [WARN] Caught keyboard interrupt (Ctrl-C)