Compare commits

...

11 commits

Author SHA1 Message Date
github-actions[bot]
222c8a2a21 [Github Action] Automated trickest wordlists update.
Some checks are pending
Readme updater - Updates readme with latest stats / update-readme (push) Waiting to run
2025-11-28 02:36:55 +00:00
ItsIgnacioPortal
5d53aebde4
feat(wordlist): Added more payloads to Swagger.txt
Closes #1250

Co-authored-by: z5jt <114263484+z5jt@users.noreply.github.com>
2025-11-27 22:49:54 -03:00
ItsIgnacioPortal
fef579420a
chore(wordlist): Removed duplicates from login_bypass.txt 2025-11-27 22:16:50 -03:00
ItsIgnacioPortal
6e9b305e78
feat(wordlist): Added more payloads to login_bypass.txt
Related to #1266

Co-authored-by: S.B <30941141+s-b-repo@users.noreply.github.com>
2025-11-27 22:13:10 -03:00
ItsIgnacioPortal
358aa6113e
chore(wordlist): Moved 'rstp.txt' wordlist from fuzzing to Discovery/Web-Content/Service-Specific 2025-11-27 22:11:51 -03:00
ItsIgnacioPortal
6655eedf33
feat(wordlist): Added OpenWRT discovery wordlist
Related to #1266

Co-authored-by: S.B <30941141+s-b-repo@users.noreply.github.com>
2025-11-27 22:08:30 -03:00
ItsIgnacioPortal
9b2eb00c82
Merge branch 'master' of github.com:danielmiessler/SecLists 2025-11-27 22:04:16 -03:00
ItsIgnacioPortal
b59ec9a363
feat(wordlist): Added RSTP camera wordlist
Closes #1214

Related to #1266

Co-authored-by: S.B <30941141+s-b-repo@users.noreply.github.com>
2025-11-27 22:03:52 -03:00
github-actions[bot]
e67f51c14c [Github Action] Automated readme update. 2025-11-28 00:54:42 +00:00
ItsIgnacioPortal
2fb3769e13
feat(wordlist): Added locale-codes wordlist and language-codes wordlist
Closes #1269
2025-11-27 21:53:18 -03:00
ItsIgnacioPortal
f6bd32b922
chore(wordlist): Added 'regional_' prefix to country codes wordlists
This will make it easier to find this wordlist in alphabetically sorted filename lists when we add locale codes and language codes

Related to #1269
2025-11-27 21:51:04 -03:00
12 changed files with 5606 additions and 802 deletions

View file

@ -1,6 +1,6 @@
{
"Jwt secrets update": {
"last_update": 1764038272
"last_update": 1764297407
},
"Trickest wordlist update": {
"last_update": 1764238080

View file

@ -2,6 +2,17 @@
These wordlists are for testing specific web-based services.
## rstp.txt
Use for: Fuzzing for RSTP camera paths.
## openwrt-luci-enpoints.txt
Use for: Fuzzing for common filepaths in routers with [OpenWRT](https://openwrt.org/) firmware.
## Microsoft-Forefront-Identity-Manager.txt
Use for: Fuzzing for common filepaths in **[Microsoft Forefront Identity Manager](https://learn.microsoft.com/en-us/previous-versions/windows/desktop/forefront-2010/ee652374(v=vs.100)) deployments.**

File diff suppressed because it is too large Load diff

View file

@ -0,0 +1,183 @@
cgi-bin/luci
cgi-bin/luci/admin
cgi-bin/luci/admin/status
cgi-bin/luci/admin/status/overview
cgi-bin/luci/admin/status/realtime
cgi-bin/luci/admin/status/processes
cgi-bin/luci/admin/status/logs
cgi-bin/luci/admin/status/connections
cgi-bin/luci/admin/status/routes
cgi-bin/luci/admin/status/firewall
cgi-bin/luci/admin/status/dmesg
cgi-bin/luci/admin/status/syslog
cgi-bin/luci/admin/status/kernel
cgi-bin/luci/admin/status/iptables
cgi-bin/luci/admin/status/bandwidth
cgi-bin/luci/admin/status/load
cgi-bin/luci/admin/status/memory
cgi-bin/luci/admin/status/traffic
cgi-bin/luci/admin/status/wireless
cgi-bin/luci/admin/status/system
cgi-bin/luci/admin/status/wan
cgi-bin/luci/admin/status/lan
cgi-bin/luci/admin/status/arp
cgi-bin/luci/admin/status/dhcp
cgi-bin/luci/admin/status/ntp
cgi-bin/luci/admin/status/uptime
cgi-bin/luci/admin/status/board
cgi-bin/luci/admin/status/diagnostics
cgi-bin/luci/admin/system
cgi-bin/luci/admin/system/admin
cgi-bin/luci/admin/system/upgrade
cgi-bin/luci/admin/system/reboot
cgi-bin/luci/admin/system/backup
cgi-bin/luci/admin/system/startup
cgi-bin/luci/admin/system/crontab
cgi-bin/luci/admin/system/leds
cgi-bin/luci/admin/system/flashops
cgi-bin/luci/admin/system/packages
cgi-bin/luci/admin/system/ssh
cgi-bin/luci/admin/system/password
cgi-bin/luci/admin/system/users
cgi-bin/luci/admin/system/groups
cgi-bin/luci/admin/system/mounts
cgi-bin/luci/admin/system/fstab
cgi-bin/luci/admin/system/hostname
cgi-bin/luci/admin/system/time
cgi-bin/luci/admin/system/ntp
cgi-bin/luci/admin/system/logging
cgi-bin/luci/admin/system/profiles
cgi-bin/luci/admin/system/upgrade/check
cgi-bin/luci/admin/system/upgrade/flash
cgi-bin/luci/admin/system/upgrade/download
cgi-bin/luci/admin/system/upgrade/config
cgi-bin/luci/admin/network
cgi-bin/luci/admin/network/interfaces
cgi-bin/luci/admin/network/wireless
cgi-bin/luci/admin/network/firewall
cgi-bin/luci/admin/network/routes
cgi-bin/luci/admin/network/dhcp
cgi-bin/luci/admin/network/diagnostics
cgi-bin/luci/admin/network/vlans
cgi-bin/luci/admin/network/switch
cgi-bin/luci/admin/network/bridges
cgi-bin/luci/admin/network/tunnels
cgi-bin/luci/admin/network/vpn
cgi-bin/luci/admin/network/pppoe
cgi-bin/luci/admin/network/mac
cgi-bin/luci/admin/network/hosts
cgi-bin/luci/admin/network/arp
cgi-bin/luci/admin/network/wan
cgi-bin/luci/admin/network/lan
cgi-bin/luci/admin/network/wifi
cgi-bin/luci/admin/network/mesh
cgi-bin/luci/admin/network/diagnostics/ping
cgi-bin/luci/admin/network/diagnostics/traceroute
cgi-bin/luci/admin/network/diagnostics/nslookup
cgi-bin/luci/admin/network/diagnostics/iperf
cgi-bin/luci/admin/network/diagnostics/speedtest
cgi-bin/luci/admin/services
cgi-bin/luci/admin/services/ddns
cgi-bin/luci/admin/services/openvpn
cgi-bin/luci/admin/services/samba
cgi-bin/luci/admin/services/upnp
cgi-bin/luci/admin/services/tor
cgi-bin/luci/admin/services/qos
cgi-bin/luci/admin/services/pppoe
cgi-bin/luci/admin/services/ftp
cgi-bin/luci/admin/services/httpd
cgi-bin/luci/admin/services/ssh
cgi-bin/luci/admin/services/tftp
cgi-bin/luci/admin/services/dnsmasq
cgi-bin/luci/admin/services/odhcpd
cgi-bin/luci/admin/services/ntpd
cgi-bin/luci/admin/services/cron
cgi-bin/luci/admin/services/firewall
cgi-bin/luci/admin/services/igmpproxy
cgi-bin/luci/admin/services/miniupnpd
cgi-bin/luci/admin/services/avahi
cgi-bin/luci/admin/services/usb
cgi-bin/luci/admin/services/printer
cgi-bin/luci/admin/services/voip
cgi-bin/luci/admin/services/mesh
cgi-bin/luci/admin/services/wifi-schedule
cgi-bin/luci/admin/services/adblock
cgi-bin/luci/admin/services/bandwidth
cgi-bin/luci/admin/services/monitoring
cgi-bin/luci/admin/services/netdata
cgi-bin/luci/admin/services/collectd
cgi-bin/luci/admin/services/grafana
cgi-bin/luci/admin/services/prometheus
cgi-bin/luci/admin/log
cgi-bin/luci/admin/log/read
cgi-bin/luci/admin/log/config
cgi-bin/luci/admin/log/system
cgi-bin/luci/admin/log/kernel
cgi-bin/luci/admin/log/firewall
cgi-bin/luci/admin/log/dhcp
cgi-bin/luci/admin/log/wifi
cgi-bin/luci/admin/log/pppoe
cgi-bin/luci/admin/log/openvpn
cgi-bin/luci/admin/log/samba
cgi-bin/luci/admin/log/ntp
cgi-bin/luci/admin/log/cron
cgi-bin/luci/admin/log/messages
cgi-bin/luci/rpc/uci
cgi-bin/luci/rpc/sys
cgi-bin/luci/rpc/auth
cgi-bin/luci/rpc/exec
cgi-bin/luci/rpc/file
cgi-bin/luci/rpc/fs
cgi-bin/luci/rpc/network
cgi-bin/luci/rpc/system
cgi-bin/luci/rpc/admin
cgi-bin/luci/rpc/user
cgi-bin/luci/rpc/config
cgi-bin/luci/rpc/status
cgi-bin/luci/rpc/log
cgi-bin/luci/rpc/backup
cgi-bin/luci/rpc/upgrade
cgi-bin/luci/rpc/diagnostics
cgi-bin/luci/rpc/wifi
cgi-bin/luci/rpc/wan
cgi-bin/luci/rpc/lan
cgi-bin/luci/rpc/firewall
cgi-bin/luci/rpc/dhcp
cgi-bin/luci/rpc/ntp
cgi-bin/luci/rpc/time
cgi-bin/luci/rpc/hostname
cgi-bin/luci/rpc/processes
cgi-bin/luci/rpc/connections
cgi-bin/luci/rpc/routes
cgi-bin/luci/rpc/arp
cgi-bin/luci/rpc/board
cgi-bin/luci/rpc/uci/get
cgi-bin/luci/rpc/uci/set
cgi-bin/luci/rpc/uci/add
cgi-bin/luci/rpc/uci/delete
cgi-bin/luci/rpc/uci/commit
cgi-bin/luci/rpc/uci/revert
cgi-bin/luci/rpc/uci/show
cgi-bin/luci/rpc/uci/list
cgi-bin/luci/rpc/sys/exec
cgi-bin/luci/rpc/sys/reboot
cgi-bin/luci/rpc/sys/upgrade
cgi-bin/luci/rpc/sys/log
cgi-bin/luci/rpc/sys/status
cgi-bin/luci/rpc/sys/info
cgi-bin/luci/rpc/sys/time
cgi-bin/luci/rpc/sys/hostname
cgi-bin/luci/rpc/sys/memory
cgi-bin/luci/rpc/sys/load
cgi-bin/luci/rpc/sys/uptime
cgi-bin/luci/rpc/sys/dmesg
cgi-bin/luci/rpc/sys/ps
cgi-bin/luci/rpc/sys/netstat
cgi-bin/luci/rpc/sys/ifconfig
cgi-bin/luci/rpc/sys/iwinfo
cgi-bin/luci/rpc/sys/iptables
cgi-bin/luci/rpc/sys/traceroute
cgi-bin/luci/rpc/sys/ping
cgi-bin/luci/rpc/sys/nslookup
cgi-bin/luci/rpc/sys/iperf
cgi-bin/luci/rpc/sys/speedtest

View file

@ -0,0 +1,193 @@
0/video1
1
1.AMP
1/1:1/main
1/cif
1/stream1
11
12
4
CAM_ID.password.mp2
CH001.sdp
GetData.cgi
H264
HighResolutionVideo
HighResolutionvideo
Image.jpg
LowResolutionVideo
MJPEG.cgi
MediaInput/h264
MediaInput/h264/stream_1
MediaInput/mpeg4
ONVIF/MediaInput
ONVIF/channel1
PSIA/Streaming/channels/0?videoCodecType=H.264
PSIA/Streaming/channels/1
PSIA/Streaming/channels/1?videoCodecType=MPEG4
PSIA/Streaming/channels/h264
Possible
ROH/channel/11
Streaming/Channels/1
Streaming/Channels/101
Streaming/Channels/102
Streaming/Channels/103
Streaming/Channels/2
Streaming/Unicast/channels/101
Streaming/channels/101
Video?Codec=MPEG4&Width=720&Height=576&Fps=30
VideoInput/1/h264/1
access_code
access_name_for_stream_1_to_5
av0_0
av0_1
av2
avn=2
axis-media/media.amp
axis-media/media.amp?videocodec=h264&resolution=640x480
cam
cam/realmonitor
cam/realmonitor?channel=1&subtype=00
cam/realmonitor?channel=1&subtype=01
cam/realmonitor?channel=1&subtype=1
cam0_0
cam0_1
cam1/h264
cam1/h264/multicast
cam1/mjpeg
cam1/mpeg4
cam1/onvif-h264
cam4/mpeg4
camera.stm
cgi-bin/viewer/video.jpg?resolution=640x480
ch0
ch0.h264
ch01.264
ch0_0.h264
ch0_unicast_firststream
ch0_unicast_secondstream
channel1
dms.jpg
dms?nowprofileid=2
h264
h264.sdp
h264/ch1/sub/
h264/media.amp
h264Preview_01_main
h264Preview_01_sub
h264_vga.sdp
image.jpg
image.mpg
image/jpeg.cgi
img/media.sav
img/video.asf
img/video.sav
ioImage/1
ipcam.sdp
ipcam/stream.cgi?nowprofileid=2
ipcam_h264.sdp
jpg/image.jpg?size=3
live
live.sdp
live/av0
live/ch0
live/ch00_0
live/ch00_1
live/ch1
live/ch2
live/h264
live/mpeg4
live0.264
live1.264
live1.sdp
live2.sdp
live3.sdp
live_h264.sdp
live_mpeg4.sdp
livestream
livestream/
media
media.amp
media/media.amp
media/video1
media/video2
media/video3
medias1
mjpeg.cgi
mjpeg/media.smp
mp4
mpeg4
mpeg4/1/media.amp
mpeg4/media.amp
mpeg4/media.amp?resolution=640x480
mpeg4/media.smp
mpeg4cif
mpeg4unicast
mpg4/rtsp.amp
multicaststream
now.mp4
nph-h264.cgi
nphMpeg4/g726-640x
nphMpeg4/g726-640x480
nphMpeg4/nil-320x240
onvif-media/media.amp
onvif/live/2
onvif1
onvif2
play1.sdp
play2.sdp
profile
recognizer
rtpvideo1.sdp
rtsp_tunnel
rtsph264
rtsph2641080p
stream1
stream2
streaming/mjpeg
synthesizer
tcp/av0_0
ucast/11
unicast/c1/s1/live
user.pin.mp2
user_defined
user=admin_password=tlJwpbo6_channel=1_stream=0.sdp?real_stream
video
video.3gp
video.cgi
video.cgi?resolution=VGA
video.cgi?resolution=vga
video.h264
video.mjpg
video.mp4
video.pro1
video.pro2
video.pro3
video/mjpg.cgi
video1
video1+audio1
video2.mjpg
videoMain
videoinput_1:0/h264_1/onvif.stm
videostream.cgi?rate=0
vis
wfov
rtsp/stream1
rtsp/stream2
rtsp/live.sdp
rtsp/channel/0
rtsp/channel/1
rtsp/channel/2
rtsp/main
rtsp/sub
rtsp/h264
rtsp/mpeg4
rtsp/av0_0
rtsp/av0_1
rtsp/unicast
rtsp/multicast
rtsp/profile1
rtsp/profile2
rtsp/profile3
rtsp/streaming/channels/101
rtsp/streaming/channels/102
rtsp/streaming/channels/103

File diff suppressed because it is too large Load diff

View file

@ -0,0 +1,123 @@
aa
af
am
ar
ay
az
be
bn
bi
bs
bg
byn
ca
cs
ch
da
de
dv
dz
el
en
et
fan
fo
fa
fj
fi
fr
ff
ga
gv
gn
ht
he
hif
hi
hr
hu
hy
id
is
it
ja
kl
ka
kk
km
rw
ky
kg
ko
kun
ku
lo
la
lv
ln
lt
lb
lu
mh
mk
mg
mt
mn
mi
ms
my
na
nr
nd
ne
nl
nn
nb
no
nrb
ny
pa
pl
pt
ps
qu
rar
rm
ro
rtm
rn
ru
sg
si
sk
sl
sm
sn
so
st
es
sq
sr
ss
ssy
sw
sv
ta
tg
th
tig
ti
to
tn
ts
tk
tr
uk
ur
uz
ve
vi
xh
zh
ms
zu

View file

@ -0,0 +1,377 @@
aa-ER
af-NA
af-ZA
am-ET
ar-EG
ar-DZ
ar-BH
ar-DJ
ar-ER
ar-IQ
ar-IL
ar-YE
ar-JO
ar-QA
ar-KM
ar-KW
ar-LB
ar-LY
ar-MA
ar-MR
ar-OM
ar-PS
ar-SA
ar-SO
ar-SD
ar-SY
ar-TD
ar-TN
ar-AE
ay-BO
az-AZ
be-BY
bn-BD
bi-VU
bs-BA
bs-ME
bg-BG
byn-ER
ca-AD
cs-CZ
ch-GU
ch-MP
da-DK
de-BE
de-DE
de-LI
de-LU
de-AT
de-CH
de-VA
dv-MV
dz-BT
el-GR
el-CY
en-AS
en-AI
en-AQ
en-AG
en-AU
en-BS
en-BB
en-BZ
en-BM
en-BW
en-IO
en-CK
en-CW
en-DM
en-ER
en-SZ
en-FK
en-FJ
en-FM
en-GM
en-GH
en-GI
en-GD
en-GU
en-GG
en-GY
en-HM
en-HK
en-IN
en-IM
en-IE
en-JM
en-JE
en-VG
en-VI
en-KY
en-CM
en-CA
en-KE
en-KI
en-UM
en-CC
en-LS
en-LR
en-MW
en-MT
en-MH
en-MU
en-MS
en-NA
en-NR
en-NZ
en-NG
en-NU
en-MP
en-NF
en-PK
en-PW
en-PG
en-PH
en-PN
en-PR
en-RW
en-MF
en-SB
en-ZM
en-WS
en-SC
en-SL
en-ZW
en-SG
en-SX
en-SH
en-KN
en-LC
en-VC
en-ZA
en-SD
en-GS
en-SS
en-TZ
en-TK
en-TO
en-TT
en-TC
en-TV
en-UG
en-VU
en-US
en-GB
en-CX
et-EE
fan-GQ
fo-FO
fa-IR
fj-FJ
fi-FI
fr-GQ
fr-BE
fr-BJ
fr-BF
fr-BI
fr-CD
fr-DJ
fr-CI
fr-FR
fr-GF
fr-PF
fr-TF
fr-MC
fr-GA
fr-GP
fr-GG
fr-GN
fr-HT
fr-JE
fr-CM
fr-CA
fr-KM
fr-LB
fr-LU
fr-MG
fr-ML
fr-MQ
fr-YT
fr-NC
fr-NE
fr-CG
fr-RE
fr-RW
fr-MF
fr-BL
fr-CH
fr-SN
fr-SC
fr-PM
fr-TG
fr-TD
fr-VU
fr-VA
fr-WF
fr-CF
ff-BF
ff-GN
ga-IE
gv-IM
gn-AR
gn-PY
ht-HT
he-IL
hif-FJ
hi-IN
hr-BA
hr-HR
hr-ME
hu-HU
hy-AM
hy-CY
id-ID
is-IS
it-IT
it-SM
it-CH
it-VA
ja-JP
kl-GL
ka-GE
kk-KZ
km-KH
rw-RW
ky-KG
kg-CD
ko-KP
ko-KR
kun-ER
ku-IQ
lo-LA
la-VA
lv-LV
ln-CD
ln-CG
lt-LT
lb-LU
lu-CD
mh-MH
mk-MK
mg-MG
mt-MT
mn-MN
mi-NZ
ms-BN
ms-SG
my-MM
na-NR
nr-ZA
nd-ZW
ne-NP
nl-AW
nl-BE
nl-CW
nl-BQ
nl-NL
nl-MF
nl-SX
nl-SR
nn-BV
nn-NO
nb-BV
nb-NO
no-BV
no-NO
no-SJ
nrb-ER
ny-MW
pa-AW
pa-CW
pl-PL
pt-AO
pt-GQ
pt-BR
pt-GW
pt-CV
pt-MO
pt-MZ
pt-TL
pt-PT
pt-ST
ps-AF
qu-BO
rar-CK
rm-CH
ro-MD
ro-RO
rtm-FJ
rn-BI
ru-AQ
ru-BY
ru-KZ
ru-KG
ru-RU
ru-TJ
ru-TM
ru-UZ
sg-CF
si-LK
sk-SK
sk-CZ
sl-SI
sm-AS
sm-WS
sn-ZW
so-SO
st-LS
st-ZA
es-GQ
es-AR
es-BZ
es-BO
es-CL
es-CR
es-DO
es-EC
es-SV
es-GU
es-GT
es-HN
es-CO
es-CU
es-MX
es-NI
es-PA
es-PY
es-PE
es-PR
es-ES
es-UY
es-VE
es-EH
sq-AL
sq-XK
sq-ME
sr-BA
sr-XK
sr-ME
sr-RS
ss-SZ
ss-ZA
ssy-ER
sw-CD
sw-KE
sw-TZ
sw-UG
sv-AX
sv-FI
sv-SE
ta-SG
ta-LK
tg-TJ
th-TH
tig-ER
ti-ER
to-TO
tn-BW
tn-ZA
ts-ZA
tk-AF
tk-TM
tr-TR
tr-CY
uk-UA
ur-PK
uz-AF
uz-UZ
ve-ZA
vi-VN
xh-ZA
zh-CN
zh-HK
zh-MO
zh-SG
zh-TW
ms-MY
zu-ZA

View file

@ -31,7 +31,7 @@ This project is maintained by [Daniel Miessler](https://danielmiessler.com/), [J
![Repo size](https://img.shields.io/github/repo-size/danielmiessler/SecLists.svg)
<!-- This badge is automatically updated by a GitHub Action. Do not edit manually. -->
![Approx cloning time](https://img.shields.io/badge/clone%20time-~%207m%2014s%20@50Mb/s-blue)
![Approx cloning time](https://img.shields.io/badge/clone%20time-~%207m%2015s%20@50Mb/s-blue)
- - -