SecLists icon indicating copy to clipboard operation
SecLists copied to clipboard

Create universally useful combined web discovery wordlists

Open heinosasshallik opened this issue 2 years ago • 6 comments

I think it would be immesely useful if SecLists had a wordlist for web discovery, which contained the unique entries from all other wordlists, sorted by commonness.

I've already done this, and I could submit a pull request to add these to your repository. In the repository I linked, there are two wordlists: one for directories and one for words. They're composed entirely of SecLists' wordlists and have been extremely helpful for hackthebox.

If you're worried about keeping them up to date, then I assume it's possible to create a github pipeline for creating these wordlists automatically.

If you'd accept these combined wordlists into your repo, then I'd try to get AutoRecon to use these as well. People on /r/oscp have been complaining that AutoRecon isn't good enough, when in reality, it just uses too small wordlists by default.

I think this small addition would make it much easier for people to have good web enumeration

heinosasshallik avatar Sep 09 '21 11:09 heinosasshallik

Wow! Yeah, these lists are handy. How did you sort them by commonness?

ItsIgnacioPortal avatar Nov 08 '21 16:11 ItsIgnacioPortal

I assumed that the smaller wordlists contained more common entries, so everything from the small wordlists should be at the top of the combined wordlist, and things that are only in the big wordlist should be towards the bottom of the wordlist.

Basically, I just cated the small wordlists first and then later sorted by unique entries

heinosasshallik avatar Nov 09 '21 09:11 heinosasshallik

Sounds good to me. Nice if there way to keep it up-to-date...

g0tmi1k avatar Nov 24 '21 10:11 g0tmi1k

I'll make a github action for it and open a PR, as soon as @heinosasshallik answers my issue on his repo ^^

ItsIgnacioPortal avatar Nov 28 '21 16:11 ItsIgnacioPortal

Answered :)

heinosasshallik avatar Nov 28 '21 21:11 heinosasshallik

I've made the pull request! #696

ItsIgnacioPortal avatar Jan 29 '22 06:01 ItsIgnacioPortal

⬆️ Looks like this can be closed?

johnsaigle avatar Sep 28 '22 20:09 johnsaigle

Yep

heinosasshallik avatar Sep 29 '22 08:09 heinosasshallik