SecLists/Discovery/Web-Content
2024-06-22 11:03:16 +00:00
..
api Update api-endpoints.txt 2023-12-06 17:22:31 +03:00
BurpSuite-ParamMiner
CMS [Github Action] Automated trickest wordlists update. 2024-06-22 10:03:27 +00:00
Domino-Hunter
dutch Removed offensive/harmful entries in files. 2024-03-29 12:29:53 -07:00
SVNDigger
trickest-robots-disallowed-wordlists [Github Action] Automated trickest wordlists update. 2024-06-22 11:03:16 +00:00
URLs Update urls-wordpress-3.3.1.txt 2023-12-27 13:28:44 -05:00
Web-Services
AdobeCQ-AEM.txt
AdobeXML.fuzz.txt
aem2.txt
Apache.fuzz.txt
apache.txt
ApacheTomcat.fuzz.txt
axis.txt
big.txt
burp-parameter-names.txt
CGI-HTTP-POST-Windows.fuzz.txt
CGI-HTTP-POST.fuzz.txt
CGI-Microsoft.fuzz.txt
CGI-XPlatform.fuzz.txt
CGIs.txt
coldfusion.txt
combined_directories.txt [Github Action] Updated combined_directories.txt 2024-06-11 17:03:09 +00:00
combined_words.txt [Github Action] Updated combined_words.txt 2024-06-11 15:10:00 +00:00
common-and-dutch.txt
common-and-french.txt
common-and-italian.txt
common-and-portuguese.txt
common-and-spanish.txt
common-api-endpoints-mazen160.txt
Common-DB-Backups.txt
Common-PHP-Filenames.txt
common.txt Merge branch 'master' into dns_add 2024-06-11 17:56:10 +02:00
CommonBackdoors-ASP.fuzz.txt
CommonBackdoors-JSP.fuzz.txt
CommonBackdoors-PHP.fuzz.txt
CommonBackdoors-PL.fuzz.txt
confluence-administration.txt
default-web-root-directory-linux.txt
default-web-root-directory-windows.txt
directory-list-1.0.txt
directory-list-2.3-big.txt Removed offensive/harmful entries in files. 2024-03-29 12:29:53 -07:00
directory-list-2.3-medium.txt Removed offensive/harmful entries in files. 2024-03-29 12:29:53 -07:00
directory-list-2.3-small.txt
directory-list-lowercase-2.3-big.txt
directory-list-lowercase-2.3-medium.txt
directory-list-lowercase-2.3-small.txt
dirsearch.txt
domino-dirs-coldfusion39.txt
domino-endpoints-coldfusion39.txt
dsstorewordlist.txt
elmah.txt
FatwireCMS.fuzz.txt
fnf-fuzz.txt
forefront-identity-management.txt
Frontpage.fuzz.txt
frontpage.txt
golang.txt
graphql.txt
hashicorp-consul-api.txt
hashicorp-vault.txt
hpsmh.txt
HTTP-POST-Microsoft.fuzz.txt
Hyperion.fuzz.txt
hyperion.txt
iis-systemweb.txt
IIS.fuzz.txt
iplanet.txt
JavaScript-Miners.txt
JavaServlets-Common.fuzz.txt
jboss.txt
Jenkins-Hudson.txt
JRun.fuzz.txt
jrun.txt
keycloak.txt Update keycloak.txt 2024-01-06 10:21:48 +03:30
KitchensinkDirectories.fuzz.txt
LinuxFileList.txt
local-ports.txt
Logins.fuzz.txt
LotusNotes.fuzz.txt
netware.txt
nginx.txt
ntlm-directories.txt Create ntlm-directories.txt 2024-03-30 17:28:41 +01:00
oauth-oidc-scopes.txt
Oracle-EBS-wordlist.txt
oracle.txt
Oracle9i.fuzz.txt
OracleAppServer.fuzz.txt
Passwords.fuzz.txt
PHP.fuzz.txt
proxy-conf.fuzz.txt
Public-Source-Repo-Issues.json
pulsesecure.txt
quickhits.txt
raft-large-directories-lowercase.txt
raft-large-directories.txt
raft-large-extensions-lowercase.txt
raft-large-extensions.txt
raft-large-files-lowercase.txt
raft-large-files.txt
raft-large-words-lowercase.txt
raft-large-words.txt
raft-medium-directories-lowercase.txt
raft-medium-directories.txt
raft-medium-extensions-lowercase.txt
raft-medium-extensions.txt
raft-medium-files-lowercase.txt
raft-medium-files.txt
raft-medium-words-lowercase.txt
raft-medium-words.txt
raft-small-directories-lowercase.txt
raft-small-directories.txt
raft-small-extensions-lowercase.txt
raft-small-extensions.txt
raft-small-files-lowercase.txt
raft-small-files.txt
raft-small-words-lowercase.txt
raft-small-words.txt
Randomfiles.fuzz.txt
README.md
reverse-proxy-inconsistencies.txt
ror.txt
Roundcube-123.txt
sap-analytics-cloud.txt
sap.txt
sharepoint-ennumeration.txt
spring-boot.txt
SunAppServerGlassfish.fuzz.txt
sunas.txt
SuniPlanet.fuzz.txt
swagger.txt feat(swagger): add openapi known paths 2024-05-18 15:44:29 +02:00
tests.txt
tftp.fuzz.txt
tomcat.txt
UnixDotfiles.fuzz.txt
uri-from-top-55-most-popular-apps.txt
url-params_from-top-55-most-popular-apps.txt
versioning_metafiles.txt
Vignette.fuzz.txt
vulnerability-scan_j2ee-websites_WEB-INF.txt
web-all-content-types.txt
web-extensions-big.txt [Github Action] Automated trickest wordlists update. 2024-06-11 16:03:51 +00:00
web-extensions.txt
web-mutations.txt
weblogic.txt
websphere.txt
wso2-enterprise-integrator.txt

Web discovery wordlists

combined_words.txt

Use for: discovering files
This list is automatically updated by a github action whenever any of the lists it's composed by is modified.

This list is a combination of the following wordlists:

  • big.txt
  • common.txt
  • raft-large-words-lowercase.txt
  • raft-large-words.txt
  • raft-medium-words-lowercase.txt
  • raft-medium-words.txt
  • raft-small-words-lowercase.txt
  • raft-small-words.txt

combined_directories.txt

Use for: discovering files and directories
This list is automatically updated by a github action whenever any of the lists it's composed by is modified.

This list is a combination of the following wordlists:

  • apache.txt
  • combined_words.txt
  • directory-list-1.0.txt
  • directory-list-2.3-big.txt
  • directory-list-2.3-medium.txt
  • directory-list-2.3-small.txt
  • raft-large-directories-lowercase.txt
  • raft-large-directories.txt
  • raft-medium-directories-lowercase.txt
  • raft-medium-directories.txt
  • raft-small-directories-lowercase.txt
  • raft-small-directories.txt

dsstorewordlist.txt

SOURCE: https://github.com/aels/subdirectories-discover

Perfect wordlist to discover directories and files on target site with tools like ffuf.

  • It was collected by parsing Alexa top-million sites for .DS_Store files (https://en.wikipedia.org/wiki/.DS_Store), extracting all the found files, and then extracting found file and directory names from around 300k real websites.
  • Then sorted by probability and removed strings with one occurrence.
  • resulted file you can download is below. Happy Hunting!

vulnerability-scan_j2ee-websites_WEB-INF.txt

Use for: discovering sensitive j2ee files exploiting a lfi

References: