Wordlists¶
Lists of usernames, passwords, and content paths used for brute forcing, spraying, and fuzzing.
Why It Matters¶
The right wordlist is often the difference between a brute-force or fuzzing attack that works and one that wastes hours. Matching the list to the target (its technology, language, and naming conventions) matters more than raw size.
Reference¶
Common Lists¶
| List | Use |
|---|---|
| SecLists | The standard collection: usernames, passwords, web content, fuzzing payloads |
| rockyou.txt | The classic leaked-password list, bundled with Kali |
| PayloadsAllTheThings | Attack payloads and fuzzing lists by category |
| dirbuster / common.txt | Web content and directory names |
Generating Targeted Lists¶
| Tool | Use |
|---|---|
| CeWL | Build a wordlist by crawling the target's website |
| CUPP | Generate password guesses from a person's details |
| crunch | Generate lists matching a known password pattern |
How I Use It¶
I start with a targeted list over a giant generic one: CeWL against the target's own site for passwords, and a technology-matched content list for fuzzing. rockyou is a reasonable fallback for password attacks, but a custom list built from OSINT usually lands faster and quieter.