Dictionaries
Lists of my most used dictionaries
Dictionary | Link | Description | Intended for | |
---|---|---|---|---|
Dotdotpwn | https://github.com/wireghoul/dotdotpwn | It's a very flexible intelligent fuzzer to discover traversal directory vulnerabilities in software such as HTTP/FTP/TFTP servers, Web platforms such as CMSs, ERPs, Blogs, etc. | Traversal directory | |
Payload all the things | https://github.com/swisskyrepo/PayloadsAllTheThings | many different resources and cheat sheets for payload generation and general methodology. | ||
Rockyou | /usr/shared/wordlists/rockyou.txt.gz | RockYou was a company that developed widgets for MySpace and implemented applications for various social networks and Facebook. Since 2014, it has engaged primarily in the purchases of rights to classic video games; it incorporates in-game ads and re-distributes the games. | ||
User agents | Seclist | Intended to bypass rate limiting (in an API) | User-agent headers | |
Windows Files | My dictionaty repo | To read interesting files from windows machines | Intended for information disclosure | |
Default Credential Cheat sheets | https://github.com/ihebski/DefaultCreds-cheat-sheet | Install and run "python3.11 creds search <service>" |
||
Insidetruest | Statistically Likelly Usernames | This resource contains wordlists for creating statistically likely usernames for use in username-enumeration, simulated password-attacks and other security testing tasks. |
Installing wordlists in your kali
You will be adding:
Installing seclist
Dictionary generators
- crunch.
- cewl.
- Common User Password Profiler: CUPP.
- Username Anarchy.
More dictionaries
- Dictionaries for cracking passwords: https://wiki.skullsecurity.org/index.php/Passwords.
- [Wordlist from wfuzz](https://github.com/xmendez/wfuzz/tree/master/wordlist.
Default credentials
Install app "Cred" from: https://github.com/ihebski/DefaultCreds-cheat-sheet
Last update: 2024-11-17 Created: January 17, 2023 20:12:35