Commit graph

876 commits

Author SHA1 Message Date
GitHub Action
7e60332510 [Github Action] Automated trickest wordlists update. 2024-01-27 00:18:07 +00:00
GitHub Action
8feab2f8a2 [Github Action] Automated trickest wordlists update. 2024-01-26 00:19:12 +00:00
GitHub Action
d2f1c0a66d [Github Action] Automated trickest wordlists update. 2024-01-25 00:20:10 +00:00
GitHub Action
5f9610a2e7 [Github Action] Automated trickest wordlists update. 2024-01-24 00:20:19 +00:00
GitHub Action
17055f5950 [Github Action] Automated trickest wordlists update. 2024-01-23 00:20:16 +00:00
GitHub Action
8d465f02f1 [Github Action] Automated trickest wordlists update. 2024-01-22 00:20:58 +00:00
GitHub Action
eee1651de7 [Github Action] Automated trickest wordlists update. 2024-01-21 00:21:58 +00:00
GitHub Action
e51f63a590 [Github Action] Automated trickest wordlists update. 2024-01-20 00:19:13 +00:00
GitHub Action
c9a1a802c7 [Github Action] Automated trickest wordlists update. 2024-01-19 00:20:01 +00:00
GitHub Action
05035b2e96 [Github Action] Automated trickest wordlists update. 2024-01-18 00:19:58 +00:00
GitHub Action
639b08f6fb [Github Action] Automated trickest wordlists update. 2024-01-17 00:19:54 +00:00
GitHub Action
3ddd3f3120 [Github Action] Automated trickest wordlists update. 2024-01-16 00:19:46 +00:00
Zerbaliy3v
16321d70b3
Merge branch 'danielmiessler:master' into master 2024-01-13 19:08:12 -05:00
GitHub Action
3464ae8e7b [Github Action] Automated trickest wordlists update. 2024-01-13 00:19:39 +00:00
GitHub Action
03cdca93fd [Github Action] Automated trickest wordlists update. 2024-01-12 00:19:49 +00:00
Zerbaliy3v
cb224ff307
Merge branch 'danielmiessler:master' into master 2024-01-11 16:20:51 -05:00
GitHub Action
9b80e32f9f [Github Action] Automated trickest wordlists update. 2024-01-11 00:19:49 +00:00
GitHub Action
b90dfbf3d1 [Github Action] Automated trickest wordlists update. 2024-01-10 00:19:55 +00:00
Zerbaliy3v
d29713089f
Merge branch 'danielmiessler:master' into master 2024-01-09 11:59:13 -05:00
GitHub Action
8a2d2fc948 [Github Action] Automated trickest wordlists update. 2024-01-09 00:20:23 +00:00
GitHub Action
b733e68e0d [Github Action] Automated trickest wordlists update. 2024-01-08 00:20:41 +00:00
GitHub Action
d770e15510 [Github Action] Automated trickest wordlists update. 2024-01-07 00:22:12 +00:00
Ali
0b23b9e802
Update keycloak.txt
updated
2024-01-06 10:21:48 +03:30
Ali
e3b87367d3
Rename Discovery/keycloak.txt to Discovery/Web-Content/keycloak.txt 2024-01-06 10:01:07 +03:30
Ali
326eba5708
Create keycloak.txt
check keycloak for sensitive paths.
2024-01-06 09:58:34 +03:30
GitHub Action
dc7f0f98a9 [Github Action] Automated trickest wordlists update. 2024-01-06 00:19:32 +00:00
Zerbaliy3v
7fb45862bb
Merge branch 'danielmiessler:master' into master 2024-01-05 11:48:07 -05:00
GitHub Action
606ab425e6 [Github Action] Automated trickest wordlists update. 2024-01-05 00:19:38 +00:00
GitHub Action
42eb032872 [Github Action] Automated trickest wordlists update. 2024-01-04 00:19:52 +00:00
Zerbaliy3v
0941bde90c
Merge branch 'danielmiessler:master' into master 2024-01-03 17:51:19 -05:00
GitHub Action
d9e19d0a8a [Github Action] Automated trickest wordlists update. 2024-01-03 00:19:31 +00:00
Zerbaliy3v
266f201aa6
Merge branch 'danielmiessler:master' into master 2024-01-02 08:31:53 -05:00
GitHub Action
6d4faa4b37 [Github Action] Automated trickest wordlists update. 2024-01-02 00:19:51 +00:00
Zerbaliy3v
d27f334ba9
Merge branch 'danielmiessler:master' into master 2024-01-01 07:03:57 -05:00
GitHub Action
238e368189 [Github Action] Automated trickest wordlists update. 2024-01-01 00:21:59 +00:00
GitHub Action
6e946ef5d6 [Github Action] Automated trickest wordlists update. 2023-12-31 00:21:19 +00:00
GitHub Action
a6f9796c8b [Github Action] Automated trickest wordlists update. 2023-12-30 00:18:42 +00:00
Zerbaliy3v
52ea9d952d
Merge branch 'danielmiessler:master' into master 2023-12-29 08:43:50 -05:00
GitHub Action
ee31873b3c [Github Action] Automated trickest wordlists update. 2023-12-29 00:16:15 +00:00
GitHub Action
950c8e3c0d [Github Action] Automated trickest wordlists update. 2023-12-28 00:19:27 +00:00
Zerbaliy3v
aac72b9a15
add site-health.min.js 2023-12-27 13:35:29 -05:00
Zerbaliy3v
a839892a20
Update urls-wordpress-3.3.1.txt 2023-12-27 13:28:44 -05:00
GitHub Action
11afd146ea [Github Action] Automated trickest wordlists update. 2023-12-27 00:18:58 +00:00
GitHub Action
7a198e1b4c [Github Action] Automated trickest wordlists update. 2023-12-26 00:19:02 +00:00
GitHub Action
36e0dcbdf2 [Github Action] Automated trickest wordlists update. 2023-12-25 00:19:59 +00:00
GitHub Action
7502c34726 [Github Action] Automated trickest wordlists update. 2023-12-24 00:21:12 +00:00
GitHub Action
4089543db6 [Github Action] Automated trickest wordlists update. 2023-12-23 00:18:40 +00:00
GitHub Action
77de539e52 [Github Action] Automated trickest wordlists update. 2023-12-22 00:19:23 +00:00
GitHub Action
22057cd6f5 [Github Action] Automated trickest wordlists update. 2023-12-21 00:19:29 +00:00
GitHub Action
8ee25d5405 [Github Action] Automated trickest wordlists update. 2023-12-20 00:16:31 +00:00
GitHub Action
9238f40902 [Github Action] Automated trickest wordlists update. 2023-12-19 00:19:49 +00:00
GitHub Action
c877027735 [Github Action] Automated trickest wordlists update. 2023-12-18 00:20:28 +00:00
GitHub Action
b19db4023a [Github Action] Automated trickest wordlists update. 2023-12-17 00:21:34 +00:00
GitHub Action
9838d9edfa [Github Action] Automated trickest wordlists update. 2023-12-16 00:19:33 +00:00
GitHub Action
959f046193 [Github Action] Automated trickest wordlists update. 2023-12-15 00:20:03 +00:00
GitHub Action
51d4e404b3 [Github Action] Automated trickest wordlists update. 2023-12-14 00:19:25 +00:00
GitHub Action
d6f7799c08 [Github Action] Automated trickest wordlists update. 2023-12-13 00:19:36 +00:00
GitHub Action
24e02cae84 [Github Action] Automated trickest wordlists update. 2023-12-12 00:19:53 +00:00
GitHub Action
071f4f787e [Github Action] Automated trickest wordlists update. 2023-12-11 00:20:35 +00:00
GitHub Action
c3ecfa278c [Github Action] Automated trickest wordlists update. 2023-12-10 00:21:29 +00:00
GitHub Action
7c091d131c [Github Action] Automated trickest wordlists update. 2023-12-09 00:19:34 +00:00
GitHub Action
ba93db25be [Github Action] Automated trickest wordlists update. 2023-12-08 00:19:53 +00:00
GitHub Action
c93ad8191b [Github Action] Automated trickest wordlists update. 2023-12-07 00:19:28 +00:00
O.o
dd1048f9a1
Merge pull request #1 from legik/patch-1
Update swagger.txt
2023-12-06 17:27:33 +03:00
O.o
cf90713af2
Update api-endpoints.txt 2023-12-06 17:22:31 +03:00
O.o
18066b02a0
Update swagger.txt 2023-12-06 17:19:17 +03:00
GitHub Action
e5929a81e0 [Github Action] Automated trickest wordlists update. 2023-12-06 00:19:51 +00:00
GitHub Action
6975f16190 [Github Action] Automated trickest wordlists update. 2023-12-05 00:19:51 +00:00
GitHub Action
2bc5aac8f4 [Github Action] Automated trickest wordlists update. 2023-12-04 00:20:01 +00:00
GitHub Action
741016b219 [Github Action] Automated trickest wordlists update. 2023-12-03 00:21:03 +00:00
GitHub Action
f1f9358a56 [Github Action] Automated trickest wordlists update. 2023-12-02 00:19:15 +00:00
GitHub Action
755772830d [Github Action] Automated trickest wordlists update. 2023-11-28 00:19:44 +00:00
GitHub Action
e707eddda6 [Github Action] Updated combined_words.txt 2023-11-27 14:01:40 +00:00
g0tmi1k
5b907778e4
Merge pull request #940 from righettod/add_4D_urls
Add 4D interesting endpoints

Source: https://doc.4d.com/4Dv18/4D/18.4/Information-about-the-Web-Site.300-5232828.en.html
2023-11-27 14:00:32 +00:00
GitHub Action
8364894040 [Github Action] Automated trickest wordlists update. 2023-11-27 00:19:49 +00:00
Dominique RIGHETTO
c1a394e443 Fix error 2023-11-26 18:31:21 +00:00
Dominique RIGHETTO
7d4b1177ee
Add 4D URL 2023-11-26 19:09:31 +01:00
molangning
9d3d08dd4b Removed empty entry 2023-11-26 13:52:39 +08:00
molangning
2030957d0b removed the extra files 2023-11-26 13:06:50 +08:00
Mo Langning
00be7dfaae cleaned files, courtesy of patch-5 2023-11-26 04:31:42 +08:00
Mo Langning
4f258f63f5 Merge branch 'patch-4' of https://github.com/molangning/SecLists into patch-4 2023-11-26 03:11:22 +08:00
Mo Langning
51ff4ba657 rename folder for clarity 2023-11-26 03:11:07 +08:00
Mo Langning
61dbd67f5f
Delete Discovery/Web-Content/RobotsDisallowed-Top500.txt 2023-11-26 03:06:58 +08:00
Mo Langning
0f9e5a3f39
Delete Discovery/Web-Content/RobotsDisallowed-Top1000.txt 2023-11-26 03:06:35 +08:00
Mo Langning
fb4f3997cd
Delete Discovery/Web-Content/RobotsDisallowed-Top100.txt 2023-11-26 03:06:11 +08:00
Mo Langning
9cca4b5645
Delete Discovery/Web-Content/RobotsDisallowed-Top10.txt 2023-11-26 03:06:00 +08:00
Mo Langning
4acacbfecb revert the borking of craftcms.txt 2023-11-26 02:39:38 +08:00
Mo Langning
a3c96905cf removed the newlines at the end 2023-11-26 02:36:15 +08:00
Mo Langning
d060c08755 renamed for clarity 2023-11-26 02:25:02 +08:00
Mo Langning
a143658516 deleted new line to shush my workflow 2023-11-26 02:21:45 +08:00
Mo Langning
fba6764444 import the files from trickest 2023-11-26 02:19:22 +08:00
g0tmi1k
197b2395e0
Merge pull request #913 from cosad3s/patch-1
Update salesforce-aura-objects.txt

https://developer.salesforce.com/docs/atlas.en-us.object_reference.meta/object_reference/sforce_api_objects_list.htm
2023-11-24 22:11:15 +00:00
Mo Langning
02b3baa0de
removed new line at the start 2023-11-24 18:56:43 +08:00
Mo Langning
a92da76486
Added missing web path 2023-11-24 18:51:59 +08:00
GitHub Action
149325ea25 [Github Action] Updated combined_words.txt 2023-11-24 10:44:35 +00:00
Mo Langning
4883481ddf
Added .well-known/humans.txt 2023-11-24 18:41:35 +08:00
g0t mi1k
75c6b9f97f Bump 2023-11-23 17:57:51 +00:00
g0tmi1k
638ce8bd32
Merge pull request #897 from adilnbabras/master
List of Files Extensions & Dutch Wordlists
2023-11-23 17:36:35 +00:00
g0tmi1k
ced93ad4ec
Merge pull request #902 from souravvvv123/sourav
Trace.axd has been added 

Source: https://www.linkedin.com/posts/therceman_bug-bounty-tips-sensitive-data-exposure-activity-6986685674506600448-wHW0/
2023-11-23 17:32:47 +00:00
g0tmi1k
b75841f60f
Merge pull request #904 from CountablyInfinite/master
added wso2 api manager endpoint /services/WorkflowCallbackService?wsdl

Source: https://apim.docs.wso2.com/en/3.2.0/develop/extending-api-manager/extending-workflows/invoking-the-api-manager-from-the-bpel-engine/
2023-11-23 17:31:56 +00:00
GitHub Action
fd4d0a7807 [Github Action] Updated combined_directories.txt 2023-11-23 17:31:36 +00:00
g0tmi1k
7dcdadeeed
Merge pull request #905 from ThomasBucaioni/master
Typos in discovery files
2023-11-23 17:30:51 +00:00
GitHub Action
af5c6419e7 [Github Action] Updated combined_words.txt 2023-11-23 17:30:12 +00:00
g0tmi1k
7606e16b66
Merge pull request #906 from DmytroKashchuk/patch-1
Update raft-medium-words.txt

Source: https://docs.spring.io/spring-boot/docs/current/reference/html/actuator.html
2023-11-23 17:29:33 +00:00
g0tmi1k
65a1d20276
Merge pull request #914 from olizimmermann/master
Certstream subdomains analysis
2023-11-23 17:22:14 +00:00
Zyaire
cb5c387a2b
Update common-http-ports.txt
Add port 8000
2023-10-23 09:50:17 +08:00
olizimmermann
81cdc0b85e added certstream subdomains analysis 2023-10-22 20:01:08 +02:00
Sébastien Copin
e275915058
Update salesforce-aura-objects.txt
Update Salesforce standard objects
2023-10-19 11:57:25 +02:00
Dmytro Kashchuk
65d8f6eb4d
Update raft-medium-words.txt
Adding "actuator" word in the list
2023-10-05 11:54:47 +02:00
ThomasBucaioni
2874a0acaa Typos 2023-09-23 09:15:11 +02:00
CountablyInfinite
59bd80122e added wso2 api manager endpoint /services/WorkflowCallbackService?wsdl 2023-09-20 20:18:49 +02:00
Sourav Chakraborty
bbbba7123e Trace.axd has been added to dirsearch.txt which can expose sensitive information about the target 2023-09-08 10:40:41 +05:30
Adil Nadeem Babras
a2133616d4
Dutch Wordlist
List of Dutch words scrape mostly from NL websites and some words collected from other sources.
2023-08-16 03:43:07 +05:00
GitHub Action
395c945627 [Github Action] Updated combined_directories.txt 2023-08-15 21:48:36 +00:00
g0tmi1k
16dd537332
Merge pull request #864 from cosad3s/master
Add PulseSecure wordlist
2023-08-15 22:31:46 +01:00
g0tmi1k
e034442490
Merge pull request #894 from dylleb/patch-1
Added .phar

Source: https://cheatsheetseries.owasp.org/cheatsheets/File_Upload_Cheat_Sheet.html#introduction
2023-08-15 22:31:22 +01:00
g0tmi1k
8b719e8a28
Merge pull request #878 from denandz/restandardize-leading-slashes
Fixes #876 - Standardize leading slases in web content discovery lists
2023-08-15 22:20:17 +01:00
GitHub Action
16048fe918 [Github Action] Updated combined_words.txt 2023-08-15 21:06:56 +00:00
lebz
83b47d72aa
Creation of web-extensions-big.txt 2023-08-14 14:23:42 +02:00
lebz
f16bde83c0
Added .phar 2023-08-14 13:32:22 +02:00
Dominique RIGHETTO
e3ae747e69
Add K8S monitoring endpoints 2023-07-27 09:21:19 +02:00
Dominique RIGHETTO
7b00abf1b7
Update objects-lowercase.txt 2023-06-06 13:02:52 +02:00
Dominique RIGHETTO
7cf06f0ae6
Update objects-uppercase.txt 2023-06-06 13:02:26 +02:00
Dominique RIGHETTO
df7ee5ce10
Update objects-lowercase.txt 2023-06-06 13:01:48 +02:00
Dominique RIGHETTO
0634488f50
Update common.txt 2023-06-01 10:27:43 +02:00
DoI
82438ac31c Standardize leading slases in web conent
Added bonus of moving ispsystem_billmanager_api.txt from CRLF to LF line
endings.
2023-05-18 23:55:53 +12:00
Dominique RIGHETTO
9cae2f8bae
Add config files 2023-05-18 08:30:06 +02:00
GitHub Action
e2b935d691 [Github Action] Updated combined_directories.txt 2023-05-16 08:56:48 +00:00
g0tmi1k
1829bf195b
Merge pull request #852 from dabasanta/danilobasanta
Dictionary of more than 5000 subdomains in Spanish
2023-05-16 09:32:35 +01:00
g0tmi1k
4001739d74
Merge pull request #860 from righettod/add_new_dict_sap-wso2
Add dict for SAP Analytics Cloud / WSO2 Entreprise Integrator.

Source: https://www.sap.com/products/technology-platform/cloud-analytics.html
https://ei.docs.wso2.com/en/latest/
https://wso2.com/integration/install/docker/community/get-started/
2023-05-16 09:31:59 +01:00
g0tmi1k
2e10810b46
Merge pull request #866 from ItsIgnacioPortal/wordpress-fuzz
Removed clutter from prematurely-merged PR (#813)
2023-05-16 09:29:56 +01:00
Ignacio J. Perez Portal
6a9dd25341 chore: Renamed "WEB-INF-dict.txt" to "vulnerability-scan_j2ee-websites_WEB-INF.txt" 2023-03-17 04:13:03 -03:00
Ignacio J. Perez Portal
62a2ec98c2 chore: sort'ed and uniq'ed wordpress.fuzz.txt 2023-03-17 04:04:55 -03:00
Ignacio J. Perez Portal
fbfe8d8da5 fix: Removed irrelevant/unjustified entries from wordpress.fuzz.txt 2023-03-17 04:03:57 -03:00
Sebastien Copin
5d1bdc3747 Update Pulse Secure VPN wordlist
Found in the wild
2023-03-10 17:31:35 +01:00
Sebastien Copin
5fb77a3f36 Add Pulse Secure VPN wordlist 2023-03-09 19:26:07 +01:00
Dominique RIGHETTO
df7a31b1d2
Add files via upload 2023-03-09 13:38:45 +01:00
GitHub Action
7fa58a2a26 [Github Action] Updated combined_words.txt 2023-03-09 12:37:53 +00:00
Dominique RIGHETTO
7732856ab9
Update common.txt 2023-03-09 13:34:32 +01:00
g0tmi1k
4a697dfe49
Merge pull request #827 from ItsIgnacioPortal/dsstore
Added dsstorewordlist.txt
2023-03-09 12:19:38 +00:00
g0tmi1k
0268599a8f
Merge pull request #833 from mhmdiaa/trickest-wordlists
Add Trickest wordlists

Source: https://github.com/trickest/inventory
2023-03-09 12:16:58 +00:00
g0tmi1k
3256414e81
Merge pull request #834 from kazet/fresher-backups-Discovery/Web-Content/quickhits.txt
Fresher backups in Discovery/Web-Content/quickhits.txt
2023-03-09 12:16:14 +00:00
g0tmi1k
92b66ac2f1
Merge pull request #836 from veritysr/master
Adding wordlist for DotNetNuke resources

Source: https://raw.githubusercontent.com/dnnsoftware/Dnn.Platform/2b530d234439f4e9cb1e0719d76c2bacd475c2d8/DNN%20Platform/Website/DotNetNuke.Website.csproj
2023-03-09 12:15:00 +00:00
g0tmi1k
96fdca5ff7
Merge pull request #837 from righettod/add-server-js-extension
Add React Server Components  file extension

Source: 
- https://blog.logrocket.com/what-you-need-to-know-about-react-server-components/
- https://blog.logrocket.com/react-server-components-nextjs-12/
2023-03-09 12:14:35 +00:00
g0tmi1k
916ba65a9f
Merge pull request #840 from its0x08/patch-1
Add new entries and sort list

Source: https://github.com/ColdFusionX/CVE-2021-26086
2023-03-09 12:13:54 +00:00
g0tmi1k
66604e14fb
Merge pull request #846 from blaiddx64/master
add **swagger-ui/ path (springfox)

Source: https://github.com/springfox/springfox/issues/3362#issuecomment-719617233
2023-03-09 12:07:56 +00:00
g0tmi1k
74e45d60cc
Merge pull request #849 from n0kovo/master
Add n0kovo_subdomains.txt

Source: https://n0kovo.github.io/posts/subdomain-enumeration-creating-a-highly-efficient-wordlist-by-scanning-the-entire-internet/
2023-03-09 12:05:43 +00:00
Adam Katora
3f7ca8a35d
Add .hta to web-extensions.txt 2023-02-25 21:09:55 -05:00
Danilo Basanta
0af12bd241 Dictionary of more than 5000 subdomains in Spanish 2023-02-21 11:11:04 -05:00
n0kovo
0c55bc0dc8 Add n0kovo_subdomains.txt 2023-02-18 02:31:03 +01:00
blaidd
f06a8c5061
remove old invalid entries of swagger-ui 2023-02-11 03:55:38 -03:00
Blaidd
74da3d7c8c
add **swagger-ui/ path 2023-02-09 10:57:16 -03:00
Mohammed Diaa
ca01196bc3 Use more descriptive names for Trickest wordlists 2023-01-16 13:58:06 +02:00
0x08
2b4afcc59e
chore: Add new entries 2023-01-05 22:20:49 +03:00
Dominique RIGHETTO
5501ad52c3 Add server.js extension 2022-12-22 15:09:37 +00:00
Dominique RIGHETTO
aed62548a5 Reset to remote master state 2022-12-22 15:05:08 +00:00
Dominique RIGHETTO
ab0fba3838 Add .server.js extension 2022-12-21 19:15:32 +00:00
sean
07e50c34d3 Adding wordlist for DotNetNuke resources 2022-12-20 14:18:21 -06:00
GitHub Action
8d45daf9fe [Github Action] Updated combined_words.txt 2022-11-27 17:44:18 +00:00
Dominique RIGHETTO
506027e8a9
Enrich content 2022-11-27 18:43:11 +01:00
Krzysztof Zając
0665d0fe72 Fresher backups in Discovery/Web-Content/quickhits.txt 2022-11-25 13:32:56 +01:00
Mohammed Diaa
28f570631a Add Trickest-Technologies wordlists 2022-11-23 13:10:46 +02:00
Mohammed Diaa
d806325fe8 Add Trickest-Robots wordlists 2022-11-23 13:09:58 +02:00
Mohammed Diaa
025f85c7df Add trickest-inventory-subdomains.txt 2022-11-23 13:08:59 +02:00
Ignacio J. Perez Portal
c859bc7d3d
Merge branch 'master' into dsstore 2022-11-23 04:21:05 +00:00
g0tmi1k
7575cbdf93
Merge pull request #828 from CountablyInfinite/master
Added content discovery for Liferay DXP default portlets
2022-11-22 12:24:31 +00:00
g0tmi1k
88552f1608
Merge pull request #804 from 0xbuz3R/patch-1
Update js.txt
2022-11-22 12:16:37 +00:00
g0tmi1k
ca9d413d7e
Merge pull request #813 from abhishekmorla/master
added new backupfiles in wordpress fuzz list

Source: https://www.linkedin.com/feed/update/urn:li:activity:6979486318774923264/
2022-11-22 12:14:19 +00:00
g0tmi1k
8d52809a0a
Merge pull request #812 from tacticthreat/patch-1
Create hashicorp-consul-api.txt

Source: HashiCorp documentation
2022-11-22 12:13:03 +00:00
g0tmi1k
e870061b86
Merge pull request #811 from tacticthreat/patch-2
Create salesforce-aura-objects.txt

Source: Salesforces' documentation
2022-11-22 12:12:18 +00:00
g0tmi1k
4296f91216
Merge pull request #810 from gypsydiver/wp-plugins-update
add site-editor and mail-masta to wp-plugins.fuzz.txt
2022-11-22 12:11:39 +00:00
g0tmi1k
517c44b24e
Merge pull request #808 from InTruder-Sec/master
Added more API directories for web application  enumeration
2022-11-22 12:10:51 +00:00
g0tmi1k
2ce0271683
Merge pull request #807 from righettod/feature_update_springboot
[spring-boot.txt] Add new endpoints

- https://docs.spring.io/spring-boot/docs/current/reference/html/application-properties.html#application-properties.actuator.management.server.base-path
- https://docs.spring.io/spring-boot/docs/current/reference/html/actuator.html#actuator.endpoints
2022-11-22 12:09:25 +00:00
g0tmi1k
76d436287d
Merge pull request #805 from its0x08/patch-1
chore: Add WEB-INF list

Source:
- https://gist.github.com/harisec/519dc6b45c6b594908c37d9ac19edbc3
- https://github.com/projectdiscovery/nuclei-templates/blob/master/vulnerabilities/generic/generic-j2ee-lfi.yaml
- https://github.com/ilmila/J2EEScan/blob/master/src/main/java/burp/j2ee/issues/impl/LFIModule.java
2022-11-22 12:08:32 +00:00
g0tmi1k
ad20e71dbc
Merge pull request #801 from righettod/feature_adobe_aem
[AdobeCQ-AEM.txt] Cleanup and enrichment.

Source: 

- https://experienceleague.adobe.com/docs/experience-manager-dispatcher/using/getting-started/security-checklist.html#restrict-access
- https://experienceleague.adobe.com/docs/experience-manager-dispatcher/using/configuring/dispatcher-configuration.html?lang=en#testing-dispatcher-security
2022-11-22 12:05:49 +00:00
g0tmi1k
2752f1bf21
Merge pull request #746 from cyberpathogen2018/patch-1
Fixed typo on line 26

Source: https://www.acunetix.com/blog/articles/a-fresh-look-on-reverse-proxy-related-attacks/
2022-11-22 12:00:42 +00:00
g0tmi1k
8d08bb324d
Merge pull request #798 from rodnt/patch-1
Spring Boot RCE involving JMX enabled

Source: https://github.com/pyn3rd/Spring-Boot-Vulnerability#0x05-spring-boot-rce-involving-jmx-enabled
2022-11-22 11:58:45 +00:00
CountablyInfinite
59ca9892ba added content discovery for liferay dxp portlets 2022-11-17 20:19:41 +01:00
PinkDev1
6362c3e275 Added dsstorewordlist.txt 2022-11-08 19:15:13 -03:00
RR
aacc4cd2c1
Removed duplicate entries
applied unique to the wordlist removing any duplicates from list
2022-10-20 11:31:56 -04:00
0x08
a218cf1a62
Merge branch 'danielmiessler:master' into patch-1 2022-10-14 15:04:02 +03:00
RR
69388e96f9
Update hashicorp-consul-api.txt
removed two comment lines
2022-10-03 14:54:49 -04:00
RR
5c356da2f6
Update salesforce-aura-objects.txt
removed comment lines
2022-10-03 13:24:28 -04:00
abhishekmorla
6f8c6e9226 added new backupfiles in wordpress fuzz list 2022-09-25 23:08:54 +05:30
RR
4bc885b5dd
Create salesforce-aura-objects.txt 2022-09-15 14:44:34 -04:00
RR
960a60fa44
Create hashicorp-consul-api.txt 2022-09-15 14:41:28 -04:00
Fernando Mendoza
62a7e2bf18 add site-editor and mail-masta 2022-09-15 04:06:39 +02:00
0x08
9aa9cbe8d8
chore: Add entry to the README.md 2022-09-11 20:29:45 +03:00
Deep Dhakate
e987cfe049
Update README.md 2022-09-09 16:51:28 +05:30
Deep Dhakate
d923f12bc2
Update README.md 2022-09-08 13:08:14 +05:30
Deep Dhakate
ec1bc6a782
Add files via upload 2022-09-08 13:05:55 +05:30
Dominique RIGHETTO
94f9cd4103
Add missing ones from last doc versions 2022-09-05 18:29:15 +02:00
Dominique RIGHETTO
390477fdc5
Add endpoints 2022-09-05 18:19:14 +02:00
GitHub Action
62e98b2e6b [Github Action] Updated awesome-environment-variable-names.txt 2022-09-01 00:11:48 +00:00
0x08
a8b1094090
chore: Add WEB-INF list
## Add `WEB-INF` list.
Used to test LFI on j2ee webapps.
### Reference: 
- [https://gist.github.com/harisec/519dc6b45c6b594908c37d9ac19edbc3](https://gist.github.com/harisec/519dc6b45c6b594908c37d9ac19edbc3)
- [https://github.com/projectdiscovery/nuclei-templates/blob/master/vulnerabilities/generic/generic-j2ee-lfi.yaml](https://github.com/projectdiscovery/nuclei-templates/blob/master/vulnerabilities/generic/generic-j2ee-lfi.yaml)
- [https://github.com/ilmila/J2EEScan/blob/master/src/main/java/burp/j2ee/issues/impl/LFIModule.java](https://github.com/ilmila/J2EEScan/blob/master/src/main/java/burp/j2ee/issues/impl/LFIModule.java)
2022-08-30 22:26:05 +03:00
d3xt4r
5ef677051c
Update js.txt 2022-08-27 01:14:03 +05:30
Dominique RIGHETTO
dadb6f6ebc
Cleanup and enhancement 2022-08-08 18:28:59 +02:00
Rodolfo Tavares
2a5e2b03a9
Spring Boot RCE involving JMX enabled
Extracted from https://github.com/pyn3rd/Spring-Boot-Vulnerability#0x05-spring-boot-rce-involving-jmx-enabled
2022-08-03 12:18:24 -03:00
GitHub Action
ef791ad197 [Github Action] Updated combined_directories.txt 2022-08-02 09:54:34 +00:00
g0tmi1k
67887612d7
Merge pull request #777 from ItsIgnacioPortal/fawesome-secrets
Added awesome-environment-variable-names.txt and an auto-updater github action

Source: https://github.com/Puliczek/awesome-list-of-secrets-in-environment-variables
2022-08-02 07:16:39 +01:00
g0tmi1k
507b65ef47
Merge pull request #701 from chashtag/master
Added more PHP web shells
2022-08-02 07:15:37 +01:00
g0tmi1k
4b2f826fed
Merge pull request #713 from TheQmaks/master
ISPSystem BillManager - list of api endpoints for hostings penetration tests

Source: https://docs.ispsystem.com/billmanager/developer-section/billmanager-api
2022-08-02 06:57:38 +01:00
g0tmi1k
20903ee7d8
Merge pull request #756 from ScreaMy7/master
List of TLDs.

Source:

https://data.iana.org/TLD/tlds-alpha-by-domain.txt
https://tld-list.com/tlds-from-a-z
https://raw.githubusercontent.com/jdgregson/TLD-List/master/newline-separated-tlds.txt
2022-08-02 06:48:14 +01:00
g0tmi1k
593324addc
Merge pull request #767 from shelld3v/patch-10
Update dirsearch.txt
2022-08-02 06:45:45 +01:00
GitHub Action
1ef4dcb96e [Github Action] Updated combined_words.txt 2022-08-02 05:34:58 +00:00
g0tmi1k
ce9f9588b7
Merge pull request #776 from ItsIgnacioPortal/fVersioning-systems
raft-small-words.txt: Added more source code versioning systems

Source: https://nitter.kavin.rocks/intigriti/status/1533050946212839424
2022-08-02 06:33:45 +01:00
g0tmi1k
348b6f3f88
Merge pull request #778 from ItsIgnacioPortal/i768
Fixes #768: Created combined_subdomains.txt and appended "preprod-payroll" to it.
2022-08-02 06:32:57 +01:00
g0tmi1k
ddd078f4ab
Merge pull request #781 from J-GainSec/patch-1
Create top-apk-params.txt

Source: 

https://gist.github.com/nullenc0de/be4d0ac216ee4fecab5493555089b28d

https://twitter.com/nullenc0de/status/1425973675715612672

https://gist.github.com/nullenc0de/e9d1f2a8a0a38c9bfcb5bdb9fc7191ea
2022-08-02 06:28:30 +01:00
g0tmi1k
b949a69cca
Merge pull request #782 from J-GainSec/patch-2
Create sharepoint.txt

Source: https://github.com/GainSec/TreeHouse-Wordlists/blob/master/Microsoft%20SharePoint.txt
2022-08-02 06:26:49 +01:00
g0tmi1k
baa6e8599b
Merge pull request #783 from J-GainSec/patch-3
Create iis-systemweb.txt

Source: https://github.com/GainSec/TreeHouse-Wordlists/blob/master/IIS_Systemweb_fuzz-WL.txt
2022-08-02 06:25:56 +01:00
g0tmi1k
7fb9827bfc
Merge pull request #784 from J-GainSec/patch-4
Create forefront-identity-management

Source: https://raw.githubusercontent.com/GainSec/TreeHouse-Wordlists/master/Microsoft-Forefront-Identity-Management-2010.txt
2022-08-02 06:25:23 +01:00
g0tmi1k
1ebd15c9e5
Merge pull request #786 from J-GainSec/patch-5
Create uri-from-top-55-most-popular-apps.txt

Source:

https://github.com/danielmiessler/SecLists/pull/781#issuecomment-1168353194

https://twitter.com/nullenc0de/status/1425973675715612672

https://gist.github.com/nullenc0de/e9d1f2a8a0a38c9bfcb5bdb9fc7191ea
2022-08-02 06:22:46 +01:00
Dominique RIGHETTO
20cb80229b
Add ssh key file name 2022-08-02 06:19:51 +02:00
GitHub Action
51bad1c320 [Github Action] Updated combined_words.txt 2022-08-01 23:11:39 +00:00
Wouter Kobes
f752b04a32 Adds activation to common.txt 2022-07-23 16:42:03 +02:00
J-GainSec
cda67688e9
Update uri-from-top-55-most-popular-apps.txt
Removed a few useless entries
2022-06-29 11:10:56 +02:00
J-GainSec
76fbcb2289
Update sharepoint-ennumeration.txt
Removed any entries with // or /// and reran uniq
2022-06-29 11:00:16 +02:00
J-GainSec
cccdb40cef
Update sharepoint-ennumeration.txt
Removed double slashes
2022-06-28 21:34:27 +02:00
J-GainSec
00cb49844d
Update and rename sharepoint.txt to sharepoint-ennumeration.txt
Changed name
2022-06-28 21:32:55 +02:00
J-GainSec
77e7ea50cf
Update uri-from-top-55-most-popular-apps.txt
Removed leading slashes.
2022-06-28 21:30:54 +02:00
J-GainSec
0a09279658
Rename forefront-identity-management to forefront-identity-management.txt 2022-06-28 15:37:41 +02:00
J-GainSec
944a8deaf0
Create uri-from-top-55-most-popular-apps.txt
Removed trailing slashes
2022-06-28 15:17:38 +02:00
J-GainSec
8cf0fbdc71
Update and rename top-apk-params.txt to url-params_from-top-55-most-popular-apps.txt
Updated name
2022-06-28 15:15:08 +02:00
J-GainSec
06b0cddb2a
Create forefront-identity-management
Sourced from https://raw.githubusercontent.com/GainSec/TreeHouse-Wordlists/master/Microsoft-Forefront-Identity-Management-2010.txt

Wordlist for Microsoft Forefront Identity Management 2010
2022-06-27 19:25:35 +02:00
J-GainSec
6a191793da
Create iis-systemweb.txt
Sourced from https://github.com/GainSec/TreeHouse-Wordlists/blob/master/IIS_Systemweb_fuzz-WL.txt

A IIS /system_web/ wordlist.
2022-06-27 19:20:19 +02:00
J-GainSec
051d84c9e7
Create sharepoint.txt
Sourced from https://github.com/GainSec/TreeHouse-Wordlists/blob/master/Microsoft%20SharePoint.txt

A Microsoft Sharepoint wordlist
2022-06-27 19:18:05 +02:00
J-GainSec
9a6b80ed19
Create top-apk-params.txt
Parameters from the Top 55 Android applications.
2022-06-27 19:06:01 +02:00
PinkDev1
1cbee5afc8 Fixed #768: Created combined_subdomains.txt and appended "preprod-payroll" to it 2022-06-23 23:03:53 -03:00
PinkDev1
baaec330cf Added awesome-environment-variable-names.txt and an auto-updater github action 2022-06-23 21:55:49 -03:00
PinkDev1
ba70a134d9 raft-small-words.txt: Added more source code versioning systems
Source: https://nitter.kavin.rocks/intigriti/status/1533050946212839424
2022-06-23 19:36:36 -03:00
Pham Sy Minh
355b691d5e
Update dirsearch.txt 2022-06-18 13:52:57 +07:00
ScreaM
b5e43148d2
Added tlds. 2022-05-11 18:47:43 +05:30
cyberpathogen2018
ab7098789d
Fixed typo on line 26
typo could result in false negative results.
2022-04-30 23:19:40 -04:00
GitHub Action
4eb28683ab [Github Action] Updated combined_words.txt 2022-04-26 16:51:13 +00:00
GitHub Action
939734974b [Github Action] Updated combined_directories.txt 2022-04-26 16:33:54 +00:00
g0tmi1k
9bf9f2ea2a
Merge pull request #696 from ItsIgnacioPortal/master
Create universally useful combined web discovery wordlists which auto-update
2022-04-26 17:32:16 +01:00
g0tmi1k
2e82613b9b
Merge pull request #712 from righettod/master
Sync with param-miner master repository.

1. Take content of the file **params** from the [PortSwigger/param-miner](https://github.com/PortSwigger/param-miner/blob/master/resources/params) repository (master branch).
2. Take the content of the file **burp-parameter-names.txt** from the [SecLists](https://github.com/danielmiessler/SecLists/blob/master/Discovery/Web-Content/burp-parameter-names.txt) repository (master branch).
3. Unify the both content removing the duplicates via `cat params  burp-parameter-names.txt | sort -u > burp-parameter-names.txt`.
4. Add the parameter named **api-version** found into this [blog post](https://medium.com/xm-cyber/10-ways-of-gaining-control-over-azure-function-apps-7e7b84367ce6) about attacking Azure function apps.
2022-04-26 17:25:07 +01:00
Ben M Stokland
a7d0fc30a1
Add Hangfire console
https://docs.hangfire.io/en/latest/configuration/using-dashboard.html
https://www.shodan.io/search?query=http.title%3A%22hangfire%22
2022-04-20 21:32:18 +02:00
Anatoliy
dcb3b852f9
Add files via upload 2022-04-13 23:44:43 +03:00
Dominique RIGHETTO
ac544a1876
Sync with param-miner master repo 2022-04-10 10:04:13 +02:00
PinkDev1
2147ad87f7
quickhits.txt: restored to its initial state
My previous two commits should've been on a different branch, Woops
2022-02-21 06:41:14 +00:00
PinkDev1
66672f7299
quickhits.txt: Added more files
Extracted from ShhGit: https://github.com/eth0izzle/shhgit/blob/master/config.yaml
2022-02-21 06:34:36 +00:00
PinkDev1
58df3b3401
quickhits.txt: Removed trailing "/" 2022-02-21 06:32:19 +00:00
chashtag
a6f336de8c removed non php shells 2022-02-09 21:42:25 -05:00
chashtag
6428e57575 Added more we shells
Removed spaces from file name
2022-02-09 21:37:00 -05:00
g0tmi1k
168584fdc6
Merge pull request #651 from cbk914/master
Spring paths update
2022-02-02 23:41:04 +00:00
g0tmi1k
a537fd9ad4
Merge pull request #693 from giper45/master
Added italian subdomains
2022-02-02 23:34:42 +00:00
Paul Werther
8b17578f93 add opcache to raft large directory list, #683 2022-02-01 15:32:17 +01:00
g0tmi1k
58370984a4
Merge pull request #687 from righettod/master
Add "h2-console" word

https://mp.weixin.qq.com/s/Yn5U8WHGJZbTJsxwUU3UiQ
https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console
https://www.shodan.io/search?query=http.title%3A%22H2+Console%22
2022-01-31 23:22:06 +00:00
g0tmi1k
5a4d4f7ebc
Merge pull request #686 from AddaxSoft/patch-2
added 8443, tomcat ssl
2022-01-31 23:21:24 +00:00