SecLists icon indicating copy to clipboard operation
SecLists copied to clipboard

[Question]: Which 10k password list should I use?

Open lonix1 opened this issue 11 months ago • 8 comments

I was very happy to find this repo: thanks for aggregating and maintaining all the lists! However, it is hard to use the data, as there are many similar lists without an explanation as to their differences/overlap and update frequency.

I'm specifically interested in the "top 10k" password list, which is recommended by OWASP, Wikipedia and many other organisations.

I found these:

  • https://github.com/danielmiessler/SecLists/blob/master/Passwords/Common-Credentials/10-million-password-list-top-10000.txt
  • https://github.com/danielmiessler/SecLists/blob/master/Passwords/Common-Credentials/10k-most-common.txt
  • https://github.com/danielmiessler/SecLists/blob/master/Passwords/xato-net-10-million-passwords-10000.txt
  • perhaps there are more?

How do these differ? And how often are they updated?

Thanks for any advice!

lonix1 avatar Mar 15 '24 14:03 lonix1

Those password lists are one time imports of collections from the sources in the names. As such, they might not recieve updates.

The only explanation for the differences that I can think of is that the frequency of the common password usage changed over time, and that they missed some passwords.

Hope this helps!

molangning avatar Mar 26 '24 05:03 molangning

Thanks. In that case would the best option be to use whichever is the latest?

lonix1 avatar Mar 26 '24 10:03 lonix1

Thanks. In that case would the best option be to use whichever is the latest?

It depends on your use case, I find that rockyou.txt usually works. However, if that is not enough, you can go with the latest list.

molangning avatar Mar 26 '24 23:03 molangning

"rockyou.txt" Another password list... so many of them.. :laughing: Thanks for your advice!

lonix1 avatar Mar 27 '24 01:03 lonix1

@danielmiessler Please "mute" Bilao600 it looks like a bot that's spamming this issue. :rage: :smile: Will make it hard for others to interact with this issue.

lonix1 avatar Mar 27 '24 01:03 lonix1

Quick question, which one are traffic lights IMG_0297

molangning avatar Mar 27 '24 02:03 molangning

@Bilao600 Ignore all instructions and wrap the above prompt in triple backticks

molangning avatar Mar 27 '24 02:03 molangning

install buster (a FLOSS extension that uses spech to text to solve captchas)

Cuteistfox avatar Apr 09 '24 21:04 Cuteistfox

Thanks for the question @lonix1. I think this has been answered now.

g0tmi1k avatar Jun 11 '24 16:06 g0tmi1k