1552 Commits

Author SHA1 Message Date
vah_13 23e94476a3 update default-passwords.csv
Add SAP passwords for CA Introscope Enterprise Manager
2022-08-22 19:55:03 +04:00
g0tmi1k c9337904d9 [Github Action] Updated LFI-etc-files-of-all-linux-packages.txt 2022-08-15 20:39:13 +00:00
Dominique RIGHETTO dadb6f6ebc Cleanup and enhancement 2022-08-08 18:28:59 +02:00
Dominique RIGHETTO 34bd1b7e77 Remove debug msg 2022-08-08 07:43:16 +02:00
Dominique RIGHETTO 15302f7f30 Add files via upload 2022-08-08 07:30:39 +02:00
Rodolfo Tavares 2a5e2b03a9 Spring Boot RCE involving JMX enabled
Extracted from https://github.com/pyn3rd/Spring-Boot-Vulnerability#0x05-spring-boot-rce-involving-jmx-enabled
2022-08-03 12:18:24 -03:00
g0tmi1k 18c4e3060f Merge pull request #797 from TalebQasem/patch-2
Updated LFI-gracefulsecurity-windows.txt

Source: https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Windows
2022-08-02 11:56:52 +01:00
Taleb Qasem b5116c1031 Update LFI-gracefulsecurity-windows.txt
Added word list from (https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Windows).
2022-08-02 16:25:02 +06:00
GitHub Action ef791ad197 [Github Action] Updated combined_directories.txt 2022-08-02 09:54:34 +00:00
g0tmi1k cb7999d274 Merge pull request #796 from g0tmi1k/2022.3
Ready for 2022.3
2022.3
2022-08-02 10:51:13 +01:00
g0t mi1k 74e6bdfe9e Refresh contributors 2022-08-02 10:50:27 +01:00
g0t mi1k 8aeb96fe31 Drop description 2022-08-02 10:50:19 +01:00
g0tmi1k b49003fdbc Merge pull request #785 from nicholas-long/master
Create list of files in that could go in /etc for fuzzing
2022-08-02 07:22:22 +01:00
g0tmi1k 67887612d7 Merge pull request #777 from ItsIgnacioPortal/fawesome-secrets
Added awesome-environment-variable-names.txt and an auto-updater github action

Source: https://github.com/Puliczek/awesome-list-of-secrets-in-environment-variables
2022-08-02 07:16:39 +01:00
g0tmi1k 507b65ef47 Merge pull request #701 from chashtag/master
Added more PHP web shells
2022-08-02 07:15:37 +01:00
g0t mi1k 324af1d66f Merge into README.md 2022-08-02 07:11:45 +01:00
g0tmi1k 7c82ca12db Merge pull request #702 from TheTechromancer/master
Added devops extensions - .test, .qa., etc. to Fuzzing/extensions-Bo0oM.txt
2022-08-02 06:59:33 +01:00
g0tmi1k 4c29963899 Merge pull request #706 from D3vil0per/patch-1
Create country-codes.txt

Source: https://www.iso.org/obp/ui/#search
2022-08-02 06:59:08 +01:00
g0tmi1k 4b2f826fed Merge pull request #713 from TheQmaks/master
ISPSystem BillManager - list of api endpoints for hostings penetration tests

Source: https://docs.ispsystem.com/billmanager/developer-section/billmanager-api
2022-08-02 06:57:38 +01:00
g0tmi1k d5ea32a684 Merge pull request #748 from ItsIgnacioPortal/Cook
README.md: Added 'Cook' to related projects
2022-08-02 06:54:42 +01:00
g0tmi1k f4c697e394 Merge pull request #751 from alins1r/patch-1
Converting 500-worst-passwords.txt.bz2 to .txt
2022-08-02 06:49:59 +01:00
g0tmi1k e9dd034c51 Merge pull request #752 from aancw/master
Add Dysco(Dynamic PHP Shell Command for RCE)

Source: http://blablabla.com/dysco.php?cmd=your_command_execution
2022-08-02 06:49:14 +01:00
g0tmi1k 20903ee7d8 Merge pull request #756 from ScreaMy7/master
List of TLDs.

Source:

https://data.iana.org/TLD/tlds-alpha-by-domain.txt
https://tld-list.com/tlds-from-a-z
https://raw.githubusercontent.com/jdgregson/TLD-List/master/newline-separated-tlds.txt
2022-08-02 06:48:14 +01:00
g0tmi1k f804d3649e Merge pull request #763 from khicks/master
Add OPNsense to default-passwords

Source: https://docs.opnsense.org/manual/gui.html
2022-08-02 06:46:37 +01:00
g0tmi1k 593324addc Merge pull request #767 from shelld3v/patch-10
Update dirsearch.txt
2022-08-02 06:45:45 +01:00
g0tmi1k c0be11b9e4 Merge pull request #769 from ivan-sincek/master
Fuzz amounts, quantities, or any other numerical values.

Source: https://research.nccgroup.com/wp-content/uploads/2020/07/common_security_issues_in_financially-orientated_web.pdf

https://github.com/ivan-sincek/amounts
2022-08-02 06:43:14 +01:00
g0tmi1k 3217b9b8f2 Merge pull request #774 from bigshika/envIds
Add common Environment identifiers
2022-08-02 06:39:31 +01:00
GitHub Action 1ef4dcb96e [Github Action] Updated combined_words.txt 2022-08-02 05:34:58 +00:00
g0tmi1k ce9f9588b7 Merge pull request #776 from ItsIgnacioPortal/fVersioning-systems
raft-small-words.txt: Added more source code versioning systems

Source: https://nitter.kavin.rocks/intigriti/status/1533050946212839424
2022-08-02 06:33:45 +01:00
g0tmi1k 348b6f3f88 Merge pull request #778 from ItsIgnacioPortal/i768
Fixes #768: Created combined_subdomains.txt and appended "preprod-payroll" to it.
2022-08-02 06:32:57 +01:00
g0tmi1k ef158b0232 Merge pull request #780 from ItsIgnacioPortal/i538
Fixes #538: Add scraped JWT secrets

Source: https://github.com/wallarm/jwt-secrets/blob/master/jwt.secrets.list
2022-08-02 06:29:35 +01:00
g0tmi1k ddd078f4ab Merge pull request #781 from J-GainSec/patch-1
Create top-apk-params.txt

Source: 

https://gist.github.com/nullenc0de/be4d0ac216ee4fecab5493555089b28d

https://twitter.com/nullenc0de/status/1425973675715612672

https://gist.github.com/nullenc0de/e9d1f2a8a0a38c9bfcb5bdb9fc7191ea
2022-08-02 06:28:30 +01:00
g0tmi1k b949a69cca Merge pull request #782 from J-GainSec/patch-2
Create sharepoint.txt

Source: https://github.com/GainSec/TreeHouse-Wordlists/blob/master/Microsoft%20SharePoint.txt
2022-08-02 06:26:49 +01:00
g0tmi1k baa6e8599b Merge pull request #783 from J-GainSec/patch-3
Create iis-systemweb.txt

Source: https://github.com/GainSec/TreeHouse-Wordlists/blob/master/IIS_Systemweb_fuzz-WL.txt
2022-08-02 06:25:56 +01:00
g0tmi1k 7fb9827bfc Merge pull request #784 from J-GainSec/patch-4
Create forefront-identity-management

Source: https://raw.githubusercontent.com/GainSec/TreeHouse-Wordlists/master/Microsoft-Forefront-Identity-Management-2010.txt
2022-08-02 06:25:23 +01:00
g0tmi1k 1ebd15c9e5 Merge pull request #786 from J-GainSec/patch-5
Create uri-from-top-55-most-popular-apps.txt

Source:

https://github.com/danielmiessler/SecLists/pull/781#issuecomment-1168353194

https://twitter.com/nullenc0de/status/1425973675715612672

https://gist.github.com/nullenc0de/e9d1f2a8a0a38c9bfcb5bdb9fc7191ea
2022-08-02 06:22:46 +01:00
g0tmi1k 2c424971ce Merge pull request #795 from righettod/feature_add_sshkeyfiles
Add additional ssh key file names

Source: `man ssh`
2022-08-02 06:20:26 +01:00
Dominique RIGHETTO 20cb80229b Add ssh key file name 2022-08-02 06:19:51 +02:00
g0tmi1k edc55381b0 Merge pull request #790 from ItsIgnacioPortal/i770
Fixes #770: Zipped files with problematic filenames
2022-08-02 00:12:52 +01:00
GitHub Action 51bad1c320 [Github Action] Updated combined_words.txt 2022-08-01 23:11:39 +00:00
g0tmi1k 00c55dbad1 Merge pull request #792 from WKobes/add-activation
Adds `activation' to common.txt
2022-08-02 00:10:19 +01:00
g0tmi1k f11c64cfc4 Merge pull request #794 from TalebQasem/patch-1
Update LFI-gracefulsecurity-linux.txt

https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Linux
2022-08-02 00:09:42 +01:00
nicholas-long 4fc6defaf5 [Github Action] Updated LFI-etc-files-of-all-linux-packages.txt 2022-08-01 21:02:56 +00:00
Taleb Qasem 294ee04ad3 Update LFI-gracefulsecurity-linux.txt
Removed 3 duplicates (/etc/passwd, /etc/mod, and /etc/php4/apache2/php.ini). Then added word list from (https://raw.githubusercontent.com/DragonJAR/Security-Wordlist/main/LFI-WordList-Linux).
2022-07-27 21:16:50 +06:00
nicholas-long b10f0fb44d [Github Action] Updated LFI-etc-files-of-all-linux-packages.txt 2022-07-25 16:47:44 +00:00
Nicholas Long f51fea3d77 enclose yaml special chars string in quotes 2022-07-25 16:36:37 +00:00
Nicholas Long ca4f454d13 update auto commit message, rename wordlist and references to it, title case in markdown headings 2022-07-25 16:26:11 +00:00
Wouter Kobes f752b04a32 Adds activation to common.txt 2022-07-23 16:42:03 +02:00
nicholas-long 44b881960a update autogenerated files 2022-07-15 20:41:15 +00:00
nicholas-long 86047fd987 update autogenerated files 2022-07-14 19:16:29 +00:00