SecLists/Discovery/Web-Content
2025-01-24 10:04:19 +00:00
..
api Improve readme files for better clarity and usage examples 2024-11-05 21:58:51 +08:00
BurpSuite-ParamMiner Rename "_" -> "-" & found a few new homes 2018-10-15 13:08:10 +01:00
CMS [Github Action] Automated trickest wordlists update. 2025-01-24 10:04:19 +00:00
Domino-Hunter Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
dutch Removed offensive/harmful entries in files. 2024-03-29 12:29:53 -07:00
SVNDigger Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
trickest-robots-disallowed-wordlists [Github Action] Automated trickest wordlists update. 2025-01-24 10:04:19 +00:00
URLs Improve readme files for better clarity and usage examples 2024-11-05 21:58:51 +08:00
Web-Services Fix #259 - Recover from bad merge 2019-01-07 15:40:56 +00:00
AdobeCQ-AEM.txt Cleanup and enhancement 2022-08-08 18:28:59 +02:00
AdobeXML.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
aem2.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Apache.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
apache.txt Add balancer for apache 2021-04-26 18:26:17 +02:00
ApacheTomcat.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
axis.txt standardisze line endings 2020-05-27 14:10:50 +01:00
big.txt Merge pull request #1073 from newyork167/master 2024-11-20 10:08:16 +00:00
burp-parameter-names.txt Sync with param-miner master repo 2022-04-10 10:04:13 +02:00
CGI-HTTP-POST-Windows.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
CGI-HTTP-POST.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
CGI-Microsoft.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
CGI-XPlatform.fuzz.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
CGIs.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
coldfusion.txt standardisze line endings 2020-05-27 14:10:50 +01:00
combined_directories.txt Added gem/rack better errors 2024-08-14 17:11:52 -04:00
combined_words.txt Added gem/rack better errors 2024-08-14 17:11:52 -04:00
common-and-dutch.txt Adds activation to common.txt 2022-07-23 16:42:03 +02:00
common-and-french.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
common-and-italian.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
common-and-portuguese.txt renamed to correct name 2020-04-07 08:52:35 -03:00
common-and-spanish.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
common-api-endpoints-mazen160.txt Add "-" to split up words, moved files since PR accepted 2018-03-05 10:30:27 +00:00
Common-DB-Backups.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Common-PHP-Filenames.txt Close #145 - Update Common_PHP_Filenames.txt (admin*.php) 2018-03-21 16:14:59 +00:00
common.txt feat(wordlist): Added more endpoints to common.txt 2025-01-02 20:37:09 -03:00
common_directories.txt feat(wordlist): created 'common_directories.txt' wordlist 2024-09-10 22:52:36 -03:00
CommonBackdoors-ASP.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
CommonBackdoors-JSP.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
CommonBackdoors-PHP.fuzz.txt removed non php shells 2022-02-09 21:42:25 -05:00
CommonBackdoors-PL.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
confluence-administration.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
default-web-root-directory-linux.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
default-web-root-directory-windows.txt Quick move about 2018-03-21 17:47:29 +00:00
directory-list-1.0.txt Discovery: Fix spelling and hyphenate some words 2021-03-13 23:23:27 +01:00
directory-list-2.3-big.txt Removed offensive/harmful entries in files. 2024-03-29 12:29:53 -07:00
directory-list-2.3-medium.txt Removed offensive/harmful entries in files. 2024-03-29 12:29:53 -07:00
directory-list-2.3-small.txt Discovery: Fix spelling and hyphenate some words 2021-03-13 23:23:27 +01:00
directory-list-lowercase-2.3-big.txt Discovery: Fix spelling and hyphenate some words 2021-03-13 23:23:27 +01:00
directory-list-lowercase-2.3-medium.txt Discovery: Fix spelling and hyphenate some words 2021-03-13 23:23:27 +01:00
directory-list-lowercase-2.3-small.txt Discovery: Fix spelling and hyphenate some words 2021-03-13 23:23:27 +01:00
dirsearch.txt Trace.axd has been added to dirsearch.txt which can expose sensitive information about the target 2023-09-08 10:40:41 +05:30
domino-dirs-coldfusion39.txt Close #291 - Fix encoding issues 2019-05-08 11:04:00 +01:00
domino-endpoints-coldfusion39.txt merged two domino endpoints files 2018-12-11 04:01:38 +02:00
dsstorewordlist.txt Added dsstorewordlist.txt 2022-11-08 19:15:13 -03:00
elmah.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
FatwireCMS.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
fnf-fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
forefront-identity-management.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Frontpage.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
frontpage.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
golang.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
graphql.txt add ___graphql to Discovery/Web-Content/graphql.txt,https://github.com/danielmiessler/SecLists/issues/642 2021-08-28 11:44:02 +08:00
hashicorp-consul-api.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
hashicorp-vault.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
hpsmh.txt standardisze line endings 2020-05-27 14:10:50 +01:00
HTTP-POST-Microsoft.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Hyperion.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
hyperion.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
iis-systemweb.txt Create iis-systemweb.txt 2022-06-27 19:20:19 +02:00
IIS.fuzz.txt remove new line at the end 2024-11-11 19:44:42 +08:00
iplanet.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
JavaScript-Miners.txt Add "-" to split up words, moved files since PR accepted 2018-03-05 10:30:27 +00:00
JavaServlets-Common.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
jboss.txt standardisze line endings 2020-05-27 14:10:50 +01:00
Jenkins-Hudson.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
JRun.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
jrun.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
keycloak.txt Update keycloak.txt 2024-01-06 10:21:48 +03:30
KitchensinkDirectories.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
LinuxFileList.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
local-ports.txt Add local ports for scan 2019-10-21 17:49:56 +02:00
Logins.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
LotusNotes.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
netware.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
nginx.txt Update nginx.txt 2021-07-31 10:28:09 +05:30
ntlm-directories.txt Create ntlm-directories.txt 2024-03-30 17:28:41 +01:00
oauth-oidc-scopes.txt Added a couple of scopes 2021-10-18 01:36:33 +00:00
Oracle-EBS-wordlist.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
oracle.txt removed new line at the start 2023-11-24 18:56:43 +08:00
Oracle9i.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
OracleAppServer.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Passwords.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
PHP.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
proxy-conf.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Public-Source-Repo-Issues.json Rename Public-Source-Repo-Issues.txt to Public-Source-Repo-Issues.json 2020-05-24 13:07:50 +02:00
pulsesecure.txt Update Pulse Secure VPN wordlist 2023-03-10 17:31:35 +01:00
quickhits.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
raft-large-directories-lowercase.txt Typos 2023-09-23 09:15:11 +02:00
raft-large-directories.txt Typos 2023-09-23 09:15:11 +02:00
raft-large-extensions-lowercase.txt Add server.js extension 2022-12-22 15:09:37 +00:00
raft-large-extensions.txt Add server.js extension 2022-12-22 15:09:37 +00:00
raft-large-files-lowercase.txt Typos 2023-09-23 09:15:11 +02:00
raft-large-files.txt Typos 2023-09-23 09:15:11 +02:00
raft-large-words-lowercase.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-large-words.txt Fix #259 - Recover from bad merge 2019-01-07 15:40:56 +00:00
raft-medium-directories-lowercase.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
raft-medium-directories.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
raft-medium-extensions-lowercase.txt Add server.js extension 2022-12-22 15:09:37 +00:00
raft-medium-extensions.txt Add server.js extension 2022-12-22 15:09:37 +00:00
raft-medium-files-lowercase.txt Add waybackverify.txt filename to raft medium and large lists 2021-07-13 13:09:49 +02:00
raft-medium-files.txt Add waybackverify.txt filename to raft medium and large lists 2021-07-13 13:09:49 +02:00
raft-medium-words-lowercase.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-medium-words.txt Update raft-medium-words.txt 2023-10-05 11:54:47 +02:00
raft-small-directories-lowercase.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
raft-small-directories.txt strip trailing whitespace 2020-05-27 14:26:51 +01:00
raft-small-extensions-lowercase.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-small-extensions.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-small-files-lowercase.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-small-files.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-small-words-lowercase.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
raft-small-words.txt raft-small-words.txt: Added more source code versioning systems 2022-06-23 19:36:36 -03:00
Randomfiles.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
README.md Merge pull request #1100 from StepSisStuck/better-readmes 2024-11-20 10:20:43 +00:00
reverse-proxy-inconsistencies.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
ror.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
Roundcube-123.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
rssfeed-files.txt Add files via upload 2024-07-04 07:57:17 +02:00
sap-analytics-cloud.txt Add files via upload 2023-03-09 13:38:45 +01:00
sap.txt Revert "Merge pull request #4 from danielmiessler/master" 2020-08-11 14:25:56 +02:00
sharepoint-ennumeration.txt Update sharepoint-ennumeration.txt 2022-06-29 11:00:16 +02:00
spring-boot.txt Merge pull request #807 from righettod/feature_update_springboot 2022-11-22 12:09:25 +00:00
SunAppServerGlassfish.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
sunas.txt standardisze line endings 2020-05-27 14:10:50 +01:00
SuniPlanet.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
swagger.txt Update swagger.txt 2024-11-21 12:42:33 +04:00
tests.txt Close #291 - Fix encoding issues 2019-05-08 11:04:00 +01:00
tftp.fuzz.txt rename 's/_/-/g' 2017-08-23 14:55:06 +01:00
tomcat.txt standardisze line endings 2020-05-27 14:10:50 +01:00
UnixDotfiles.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
uri-from-top-55-most-popular-apps.txt Update uri-from-top-55-most-popular-apps.txt 2022-06-29 11:10:56 +02:00
url-params_from-top-55-most-popular-apps.txt Update and rename top-apk-params.txt to url-params_from-top-55-most-popular-apps.txt 2022-06-28 15:15:08 +02:00
versioning_metafiles.txt Create versioning_metafiles.txt 2021-02-20 20:41:53 +01:00
Vignette.fuzz.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
vulnerability-scan_j2ee-websites_WEB-INF.txt chore: Renamed "WEB-INF-dict.txt" to "vulnerability-scan_j2ee-websites_WEB-INF.txt" 2023-03-17 04:13:03 -03:00
web-all-content-types.txt Merge branch 'master' into sync 2024-12-20 02:45:55 -03:00
web-extensions-big.txt Added .vue file extension at web-extensions-big, reference : https://vuejs.org/api/sfc-spec 2024-11-22 06:46:22 +08:00
web-extensions.txt added .json 2024-11-11 02:15:04 +08:00
web-mutations.txt Add VIM and NANO backup file 2019-10-11 15:55:38 +02:00
weblogic.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
websphere.txt Standardize leading slases in web conent 2023-05-18 23:55:53 +12:00
wso2-enterprise-integrator.txt added wso2 api manager endpoint /services/WorkflowCallbackService?wsdl 2023-09-20 20:18:49 +02:00

Web discovery wordlists

combined_words.txt

Overview

This list is a combination of the following wordlists:

  • big.txt
  • common.txt
  • raft-large-words-lowercase.txt
  • raft-large-words.txt
  • raft-medium-words-lowercase.txt
  • raft-medium-words.txt
  • raft-small-words-lowercase.txt
  • raft-small-words.txt

Usage

Use for: discovering files

Source

This list is automatically updated by a GitHub action whenever any of the lists it's composed by is modified.

combined_directories.txt

Overview

This list is a combination of the following wordlists:

  • apache.txt
  • combined_words.txt
  • directory-list-1.0.txt
  • directory-list-2.3-big.txt
  • directory-list-2.3-medium.txt
  • directory-list-2.3-small.txt
  • raft-large-directories-lowercase.txt
  • raft-large-directories.txt
  • raft-medium-directories-lowercase.txt
  • raft-medium-directories.txt
  • raft-small-directories-lowercase.txt
  • raft-small-directories.txt
  • common_directories.txt

Usage

Use for: discovering files and directories

Source

This list is automatically updated by a GitHub action whenever any of the lists it's composed by is modified.

dsstorewordlist.txt

Overview

Perfect wordlist to discover directories and files on target site with tools like ffuf.

Usage

Use for: discovering directories and files

Source

Source: https://github.com/aels/subdirectories-discover

References

  • It was collected by parsing Alexa top-million sites for .DS_Store files (https://en.wikipedia.org/wiki/.DS_Store), extracting all the found files, and then extracting found file and directory names from around 300k real websites.
  • Then sorted by probability and removed strings with one occurrence.
  • resulted file you can download is below. Happy Hunting!

vulnerability-scan_j2ee-websites_WEB-INF.txt

Overview

Use for: discovering sensitive j2ee files exploiting a lfi

References