Wordlists
Collection of wordlists for password cracking, directory brute-forcing, and security testing
Trickest Wordlists
View on GitHubReal-world infosec wordlists, updated regularly
Technologies
Wordlists based on source code of CMSes/servers/frameworks
- Wordpress(base, all-levels)
- Joomla(base, all-levels)
- Drupal(base, all-levels)
- Magento(base, all-levels)
- Ghost(base, all-levels)
- Tomcat(base, all-levels)
Robots
Robots.txt Allow and Disallow paths from top websites
Inventory Subdomains
1.4 million words from subdomains of 50+ public bug bounty programs
Cloud Subdomains
940k words from subdomains extracted from SSL certificates
kkrypt0nn Wordlists
View on GitHubYet another collection of wordlists
Discovery
- Apache
- Apache User Enum 1.0
- Apache User Enum 2.0
- Big
- Common
- Common SQL Columns
- Common SQL Tables
- Conf
- Directories
- Directory List 1.0
- Directory List 2.3 Medium
- Directory List 2.3 Small
- Directory List Lowercase 2.3 Medium
- Directory List Lowercase 2.3 Small
- Extensions Common
- Fuzz Php Special
- Gitignore
- Indexes
- Joomla
- JSP
- LFI All
- LFI Unix
- LFI Windows
- Most Common
- Robots
- Sensitive Files Unix
- Sensitive Files Windows
- Swagger
- TLDs
- Top Subdomains
- WP Plugins
- WP Themes
Famous
- Dnsmap
- Facebook Phished
- Fasttrack
- Fern Wifi
- Hotmail
- Rockyou
HTB
- 2 Digits
- 3 Digits
- 4 Digits
- Directories
- Gitignore
- Subdomains
- Users
Languages
- Arabic
- Croatian
- Czech
- Danish
- Dutch
- English
- French
- Georgian
- German
- Hebrew
- Italian
- Norwegian
- Polish
- Portuguese
- Russian
- Serbian
- Spanish
- Swedish
- Turkish
- Ukrainian
Passwords
- 000Webhost
- Bt4 Passwords
- Burnett
- Common Passwords Win
- Common Roots
- Darkweb 2017
- Db2 Default Passwords
- Default Passwords For Services
- Dutch Passwords
- Hak5
- Honeynet
- HTTP Default Passwords
- Indian Passwords
- Ipmi Passwords
- Keyboard Patterns
- Md5Decryptor
- Medical Devices Passwords
- Mirai Passwords
- Most Used Passwords
- Most Used Passwords Ncsc
- Nord VPN
- Openwall
- Password
- Postgres Default Passwords
- Probable WPA
- Tomcat Mgr Default Passwords
- Top Adobe Passwords
- Unix Passwords
- Xato Net Passwords
Vulnerabilities
- All Attacks
- Apache
- Axis
- Cgis
- Coldfusion
- Directory Traversal
- Directory Traversal Unix
- Directory Traversal Win
- Domino
- Fatwire
- Fatwire Pagenames
- Front Pages
- Hpsmh
- Iis
- Iplanet
- Jboss
- Jrun
- Netware
- Oracle
- Ror
- Sap
- Sharepoint
- SQL
- SQL Inj
- Ssti
- Sunas
- Tests
- Tomcat
- Vignette
- Weblogic
- Websphere
- XSS
- XXE
OneListForAll
View on GitHubRockyou for web fuzzing
Available Wordlists
onelistforallmicro.txt
Manually crafted wordlist for low hanging fruits
onelistforallshort.txt
Shortened version with a lot of content
onelistforall.txt
Complete wordlist with everything
These wordlists are intended solely for ethical and legal purposes, such as security research, legally authorized penetration testing, and educational use. Unauthorized or illegal use is strictly prohibited.