Skip to main content

Tag: Bruteforce

HowTo customize wordlist

# General wordlist manipulation

https://github.com/glitchedgitz/cook
“A wordlist framework to fullfill your kinks with your wordlists.”

“An overpower wordlist generator, splitter, merger, finder, saver, create words permutation and combinations, apply different encoding/decoding and everything you need.”

Can do anything (except targeted wordlist creation)

## Dedupe

https://github.com/nil0x42/duplicut
“Remove duplicates from MASSIVE wordlist, without sorting it (for dictionary-based password cracking)”

HowTo create wordlist

# Using info on person

simple with interactive mode (+ the most new): https://github.com/r3nt0n/bopscrk

# When person probably uses passphrase

https://github.com/initstring/passphrase-wordlist

# There are also:

https://github.com/Mebus/cupp - last update 2020 https://github.com/LandGrey/pydictor - last update 2017 https://github.com/sc0tfree/mentalist - last update 2017 - GUI with support for generating rules for hashcat and John?

ListOf wordlists

# Web

Rockyou for web dirs - six2dez/OneListForAll. It have

  • micro - 26K lines - “manally crafted wordlist for low hanging fruits”
  • short - 900K lines - a short version, it also contains a lot of things, but in a more affordable way

Special pathes - LFI, juicy APIs, misconfigurations.. etc - ayoubfathi/leaky-paths

Platform specific (drupal,wordpress…) - trickest/wordlists

Common sensitive points - RobotsDisallowed

A lot of stuff. - Seclist

# Passes

## The most used passwords

Combo of all wordlists with count of how much times is used - berzerk0/Probable-Wordlists