SecLists/Discovery/Web-Content
github-actions[bot] 8be66a50d8 [Github Action] Automated trickest wordlists update. 2024-07-06 11:03:10 +00:00
..
BurpSuite-ParamMiner Rename "_" -> "-" & found a few new homes 2018-10-15 13:08:10 +01:00
CMS [Github Action] Automated trickest wordlists update. 2024-07-06 10:03:32 +00:00
Domino-Hunter Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
SVNDigger Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
URLs Update urls-wordpress-3.3.1.txt 2023-12-27 13:28:44 -05:00
Web-Services Fix #259 - Recover from bad merge 2019-01-07 15:40:56 +00:00
api Update api-endpoints.txt 2023-12-06 17:22:31 +03:00
dutch Removed offensive/harmful entries in files. 2024-03-29 12:29:53 -07:00
trickest-robots-disallowed-wordlists [Github Action] Automated trickest wordlists update. 2024-07-06 11:03:10 +00:00
AdobeCQ-AEM.txt Cleanup and enhancement 2022-08-08 18:28:59 +02:00
AdobeXML.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Apache.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
ApacheTomcat.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
CGI-HTTP-POST-Windows.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
CGI-HTTP-POST.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
CGI-Microsoft.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
CGI-XPlatform.fuzz.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
CGIs.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Common-DB-Backups.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Common-PHP-Filenames.txt Close #145 - Update Common_PHP_Filenames.txt (admin*.php) 2018-03-21 16:14:59 +00:00
CommonBackdoors-ASP.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
CommonBackdoors-JSP.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
CommonBackdoors-PHP.fuzz.txt removed non php shells 2022-02-09 21:42:25 -05:00
CommonBackdoors-PL.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
FatwireCMS.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Frontpage.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
HTTP-POST-Microsoft.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Hyperion.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
IIS.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
JRun.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
JavaScript-Miners.txt Add "-" to split up words, moved files since PR accepted 2018-03-05 10:30:27 +00:00
JavaServlets-Common.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Jenkins-Hudson.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
KitchensinkDirectories.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
LinuxFileList.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Logins.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
LotusNotes.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Oracle-EBS-wordlist.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Oracle9i.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
OracleAppServer.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
PHP.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Passwords.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Public-Source-Repo-Issues.json Rename Public-Source-Repo-Issues.txt to Public-Source-Repo-Issues.json 2020-05-24 13:07:50 +02:00
README.md chore: Renamed "WEB-INF-dict.txt" to "vulnerability-scan_j2ee-websites_WEB-INF.txt" 2023-03-17 04:13:03 -03:00
Randomfiles.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Roundcube-123.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
SunAppServerGlassfish.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
SuniPlanet.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
UnixDotfiles.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Vignette.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
aem2.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
apache.txt Add balancer for apache 2021-04-26 18:26:17 +02:00
axis.txt standardisze line endings 2020-05-27 14:10:50 +01:00
big.txt adding "dismiss" to big.txt 2021-08-22 22:54:33 +02:00
burp-parameter-names.txt Sync with param-miner master repo 2022-04-10 10:04:13 +02:00
coldfusion.txt standardisze line endings 2020-05-27 14:10:50 +01:00
combined_directories.txt [Github Action] Updated combined_directories.txt 2024-06-11 17:03:09 +00:00
combined_words.txt [Github Action] Updated combined_words.txt 2024-06-11 15:10:00 +00:00
common-and-dutch.txt Adds activation to common.txt 2022-07-23 16:42:03 +02:00
common-and-french.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
common-and-italian.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
common-and-portuguese.txt renamed to correct name 2020-04-07 08:52:35 -03:00
common-and-spanish.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
common-api-endpoints-mazen160.txt Add "-" to split up words, moved files since PR accepted 2018-03-05 10:30:27 +00:00
common.txt Merge branch 'master' into dns_add 2024-06-11 17:56:10 +02:00
confluence-administration.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
default-web-root-directory-linux.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
default-web-root-directory-windows.txt Quick move about 2018-03-21 17:47:29 +00:00
directory-list-1.0.txt Discovery: Fix spelling and hyphenate some words 2021-03-13 23:23:27 +01:00
directory-list-2.3-big.txt Removed offensive/harmful entries in files. 2024-03-29 12:29:53 -07:00
directory-list-2.3-medium.txt Removed offensive/harmful entries in files. 2024-03-29 12:29:53 -07:00
directory-list-2.3-small.txt Discovery: Fix spelling and hyphenate some words 2021-03-13 23:23:27 +01:00
directory-list-lowercase-2.3-big.txt Discovery: Fix spelling and hyphenate some words 2021-03-13 23:23:27 +01:00
directory-list-lowercase-2.3-medium.txt Discovery: Fix spelling and hyphenate some words 2021-03-13 23:23:27 +01:00
directory-list-lowercase-2.3-small.txt Discovery: Fix spelling and hyphenate some words 2021-03-13 23:23:27 +01:00
dirsearch.txt Trace.axd has been added to dirsearch.txt which can expose sensitive information about the target 2023-09-08 10:40:41 +05:30
domino-dirs-coldfusion39.txt Close #291 - Fix encoding issues 2019-05-08 11:04:00 +01:00
domino-endpoints-coldfusion39.txt merged two domino endpoints files 2018-12-11 04:01:38 +02:00
dsstorewordlist.txt Added dsstorewordlist.txt 2022-11-08 19:15:13 -03:00
elmah.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
fnf-fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
forefront-identity-management.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
frontpage.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
golang.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
graphql.txt add ___graphql to Discovery/Web-Content/graphql.txt,https://github.com/danielmiessler/SecLists/issues/642 2021-08-28 11:44:02 +08:00
hashicorp-consul-api.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
hashicorp-vault.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
hpsmh.txt standardisze line endings 2020-05-27 14:10:50 +01:00
hyperion.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
iis-systemweb.txt Create iis-systemweb.txt 2022-06-27 19:20:19 +02:00
iplanet.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
jboss.txt standardisze line endings 2020-05-27 14:10:50 +01:00
jrun.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
keycloak.txt Update keycloak.txt 2024-01-06 10:21:48 +03:30
local-ports.txt Add local ports for scan 2019-10-21 17:49:56 +02:00
netware.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
nginx.txt Update nginx.txt 2021-07-31 10:28:09 +05:30
ntlm-directories.txt Create ntlm-directories.txt 2024-03-30 17:28:41 +01:00
oauth-oidc-scopes.txt Added a couple of scopes 2021-10-18 01:36:33 +00:00
oracle.txt removed new line at the start 2023-11-24 18:56:43 +08:00
proxy-conf.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
pulsesecure.txt Update Pulse Secure VPN wordlist 2023-03-10 17:31:35 +01:00
quickhits.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
raft-large-directories-lowercase.txt Typos 2023-09-23 09:15:11 +02:00
raft-large-directories.txt Typos 2023-09-23 09:15:11 +02:00
raft-large-extensions-lowercase.txt Add server.js extension 2022-12-22 15:09:37 +00:00
raft-large-extensions.txt Add server.js extension 2022-12-22 15:09:37 +00:00
raft-large-files-lowercase.txt Typos 2023-09-23 09:15:11 +02:00
raft-large-files.txt Typos 2023-09-23 09:15:11 +02:00
raft-large-words-lowercase.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-large-words.txt Fix #259 - Recover from bad merge 2019-01-07 15:40:56 +00:00
raft-medium-directories-lowercase.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
raft-medium-directories.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
raft-medium-extensions-lowercase.txt Add server.js extension 2022-12-22 15:09:37 +00:00
raft-medium-extensions.txt Add server.js extension 2022-12-22 15:09:37 +00:00
raft-medium-files-lowercase.txt Add waybackverify.txt filename to raft medium and large lists 2021-07-13 13:09:49 +02:00
raft-medium-files.txt Add waybackverify.txt filename to raft medium and large lists 2021-07-13 13:09:49 +02:00
raft-medium-words-lowercase.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-medium-words.txt Update raft-medium-words.txt 2023-10-05 11:54:47 +02:00
raft-small-directories-lowercase.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
raft-small-directories.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
raft-small-extensions-lowercase.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-small-extensions.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-small-files-lowercase.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-small-files.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-small-words-lowercase.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-small-words.txt raft-small-words.txt: Added more source code versioning systems 2022-06-23 19:36:36 -03:00
reverse-proxy-inconsistencies.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
ror.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
sap-analytics-cloud.txt Add files via upload 2023-03-09 13:38:45 +01:00
sap.txt Revert "Merge pull request #4 from danielmiessler/master" 2020-08-11 14:25:56 +02:00
sharepoint-ennumeration.txt Update sharepoint-ennumeration.txt 2022-06-29 11:00:16 +02:00
spring-boot.txt Merge pull request #807 from righettod/feature_update_springboot 2022-11-22 12:09:25 +00:00
sunas.txt standardisze line endings 2020-05-27 14:10:50 +01:00
swagger.txt feat(swagger): add openapi known paths 2024-05-18 15:44:29 +02:00
tests.txt Close #291 - Fix encoding issues 2019-05-08 11:04:00 +01:00
tftp.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
tomcat.txt standardisze line endings 2020-05-27 14:10:50 +01:00
uri-from-top-55-most-popular-apps.txt Update uri-from-top-55-most-popular-apps.txt 2022-06-29 11:10:56 +02:00
url-params_from-top-55-most-popular-apps.txt Update and rename top-apk-params.txt to url-params_from-top-55-most-popular-apps.txt 2022-06-28 15:15:08 +02:00
versioning_metafiles.txt Create versioning_metafiles.txt 2021-02-20 20:41:53 +01:00
vulnerability-scan_j2ee-websites_WEB-INF.txt chore: Renamed "WEB-INF-dict.txt" to "vulnerability-scan_j2ee-websites_WEB-INF.txt" 2023-03-17 04:13:03 -03:00
web-all-content-types.txt refreshed content-types from www.iana.org/assignments/media-types/media-types.xml 2020-11-17 11:48:56 +00:00
web-extensions-big.txt [Github Action] Automated trickest wordlists update. 2024-06-11 16:03:51 +00:00
web-extensions.txt Added .phar 2023-08-14 13:32:22 +02:00
web-mutations.txt Add VIM and NANO backup file 2019-10-11 15:55:38 +02:00
weblogic.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
websphere.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
wso2-enterprise-integrator.txt added wso2 api manager endpoint /services/WorkflowCallbackService?wsdl 2023-09-20 20:18:49 +02:00

README.md

Web discovery wordlists

combined_words.txt

Use for: discovering files
This list is automatically updated by a github action whenever any of the lists it's composed by is modified.

This list is a combination of the following wordlists:

  • big.txt
  • common.txt
  • raft-large-words-lowercase.txt
  • raft-large-words.txt
  • raft-medium-words-lowercase.txt
  • raft-medium-words.txt
  • raft-small-words-lowercase.txt
  • raft-small-words.txt

combined_directories.txt

Use for: discovering files and directories
This list is automatically updated by a github action whenever any of the lists it's composed by is modified.

This list is a combination of the following wordlists:

  • apache.txt
  • combined_words.txt
  • directory-list-1.0.txt
  • directory-list-2.3-big.txt
  • directory-list-2.3-medium.txt
  • directory-list-2.3-small.txt
  • raft-large-directories-lowercase.txt
  • raft-large-directories.txt
  • raft-medium-directories-lowercase.txt
  • raft-medium-directories.txt
  • raft-small-directories-lowercase.txt
  • raft-small-directories.txt

dsstorewordlist.txt

SOURCE: https://github.com/aels/subdirectories-discover

Perfect wordlist to discover directories and files on target site with tools like ffuf.

  • It was collected by parsing Alexa top-million sites for .DS_Store files (https://en.wikipedia.org/wiki/.DS_Store), extracting all the found files, and then extracting found file and directory names from around 300k real websites.
  • Then sorted by probability and removed strings with one occurrence.
  • resulted file you can download is below. Happy Hunting!

vulnerability-scan_j2ee-websites_WEB-INF.txt

Use for: discovering sensitive j2ee files exploiting a lfi

References: