1580 Commits

Author SHA1 Message Date
g0tmi1k
3256414e81
Merge pull request #834 from kazet/fresher-backups-Discovery/Web-Content/quickhits.txt
Fresher backups in Discovery/Web-Content/quickhits.txt
2023-03-09 12:16:14 +00:00
g0tmi1k
92b66ac2f1
Merge pull request #836 from veritysr/master
Adding wordlist for DotNetNuke resources

Source: https://raw.githubusercontent.com/dnnsoftware/Dnn.Platform/2b530d234439f4e9cb1e0719d76c2bacd475c2d8/DNN%20Platform/Website/DotNetNuke.Website.csproj
2023-03-09 12:15:00 +00:00
g0tmi1k
96fdca5ff7
Merge pull request #837 from righettod/add-server-js-extension
Add React Server Components  file extension

Source: 
- https://blog.logrocket.com/what-you-need-to-know-about-react-server-components/
- https://blog.logrocket.com/react-server-components-nextjs-12/
2023-03-09 12:14:35 +00:00
g0tmi1k
916ba65a9f
Merge pull request #840 from its0x08/patch-1
Add new entries and sort list

Source: https://github.com/ColdFusionX/CVE-2021-26086
2023-03-09 12:13:54 +00:00
g0tmi1k
f149f50c82
Merge pull request #845 from spmedia/patch-1
Update backdoor_list.txt
2023-03-09 12:08:20 +00:00
g0tmi1k
66604e14fb
Merge pull request #846 from blaiddx64/master
add **swagger-ui/ path (springfox)

Source: https://github.com/springfox/springfox/issues/3362#issuecomment-719617233
2023-03-09 12:07:56 +00:00
g0tmi1k
74e45d60cc
Merge pull request #849 from n0kovo/master
Add n0kovo_subdomains.txt

Source: https://n0kovo.github.io/posts/subdomain-enumeration-creating-a-highly-efficient-wordlist-by-scanning-the-entire-internet/
2023-03-09 12:05:43 +00:00
g0tmi1k
2b5942e92f
Merge pull request #850 from n0kovo/danish_wordlists
Add misc Danish wordlists

Source: https://github.com/n0kovo/danish-wordlists
2023-03-09 12:04:49 +00:00
g0tmi1k
d45a87ecaf
Merge pull request #853 from cosad3s/master
Add PHP magic methods list

Source: https://www.php.net/manual/en/language.oop5.magic.php
2023-03-09 12:00:43 +00:00
g0tmi1k
6102f31b24
Merge pull request #855 from Pri3st/update-1
Added some commonly used rotated corpotate passwords.
2023-03-09 12:00:22 +00:00
g0tmi1k
734b6556ab
Merge pull request #857 from akatora28/patch-1
Add .hta to web-extensions.txt
2023-03-09 11:59:22 +00:00
Adam Katora
3f7ca8a35d
Add .hta to web-extensions.txt 2023-02-25 21:09:55 -05:00
Marios K. Pappas
b8a5b67a5a
Added some commonly used rotated passwords.
This wordlist contains some commonly used passwords that can be found in O365, OWA, and Active Directory environments. They are oriented toward password spraying once the tester gets hold of a list of valid email addresses. The wordlist can be easily modified (e.g testers can change the COMPANY SPORTS_TEAM/HOBBY, LOCATION, and DEPARTMENT values to match their current target).
2023-02-22 19:42:58 +02:00
Sébastien Copin
18120d94f2 Add PHP magic methods list
See: https://www.php.net/manual/en/language.oop5.magic.php
2023-02-21 21:01:07 +01:00
n0kovo
a11cdca317 Change directory name 2023-02-18 03:04:40 +01:00
n0kovo
1d4d11d07b Add misc Danish wordlists 2023-02-18 03:02:32 +01:00
n0kovo
0c55bc0dc8 Add n0kovo_subdomains.txt 2023-02-18 02:31:03 +01:00
blaidd
f06a8c5061
remove old invalid entries of swagger-ui 2023-02-11 03:55:38 -03:00
Blaidd
74da3d7c8c
add **swagger-ui/ path 2023-02-09 10:57:16 -03:00
Edmond Major III
fb849ef120
Update backdoor_list.txt
- Sort A -> Z
- Find and remove duplicate entries
2023-02-03 14:00:09 -06:00
0x08
2b4afcc59e
chore: Add new entries 2023-01-05 22:20:49 +03:00
Dominique RIGHETTO
5501ad52c3 Add server.js extension 2022-12-22 15:09:37 +00:00
Dominique RIGHETTO
aed62548a5 Reset to remote master state 2022-12-22 15:05:08 +00:00
Dominique RIGHETTO
ab0fba3838 Add .server.js extension 2022-12-21 19:15:32 +00:00
sean
07e50c34d3 Adding wordlist for DotNetNuke resources 2022-12-20 14:18:21 -06:00
GitHub Action
8d45daf9fe [Github Action] Updated combined_words.txt 2022-11-27 17:44:18 +00:00
Dominique RIGHETTO
506027e8a9
Enrich content 2022-11-27 18:43:11 +01:00
Krzysztof Zając
0665d0fe72 Fresher backups in Discovery/Web-Content/quickhits.txt 2022-11-25 13:32:56 +01:00
g0tmi1k
decd3cb559
Merge pull request #831 from g0tmi1k/master
Update contributors (2022.4)
2022.4
2022-11-22 12:56:36 +00:00
g0t mi1k
c44e49aa3c Update contributors (2022.4) 2022-11-22 12:54:06 +00:00
g0tmi1k
7575cbdf93
Merge pull request #828 from CountablyInfinite/master
Added content discovery for Liferay DXP default portlets
2022-11-22 12:24:31 +00:00
g0tmi1k
9df8137868
Merge pull request #825 from its0x08/patch-2
Dedupe wordlists
2022-11-22 12:23:09 +00:00
g0tmi1k
cd30475c1a
Merge pull request #824 from cosad3s/master
fuzz-Bo0oM.txt: "WAF friendly" version
2022-11-22 12:22:36 +00:00
g0tmi1k
65a2170f83
Merge pull request #822 from ItsIgnacioPortal/etc_files_github_action
Fixed etc files github action
2022-11-22 12:20:55 +00:00
g0tmi1k
88552f1608
Merge pull request #804 from 0xbuz3R/patch-1
Update js.txt
2022-11-22 12:16:37 +00:00
g0tmi1k
ad92e2255c
Merge pull request #817 from ItsIgnacioPortal/master
Fix github action "Wordlist Updater - Awesome list of secrets in environment variables"
2022-11-22 12:16:00 +00:00
g0tmi1k
eb3803c324
Merge pull request #815 from hakxcore/patch-1
Update CommonAdminBase64.txt
2022-11-22 12:15:19 +00:00
g0tmi1k
b8b0cde981
Merge pull request #814 from xmagor/master
Update LFI-Jhaddix.txt
2022-11-22 12:14:41 +00:00
g0tmi1k
ca9d413d7e
Merge pull request #813 from abhishekmorla/master
added new backupfiles in wordpress fuzz list

Source: https://www.linkedin.com/feed/update/urn:li:activity:6979486318774923264/
2022-11-22 12:14:19 +00:00
g0tmi1k
8d52809a0a
Merge pull request #812 from tacticthreat/patch-1
Create hashicorp-consul-api.txt

Source: HashiCorp documentation
2022-11-22 12:13:03 +00:00
g0tmi1k
e870061b86
Merge pull request #811 from tacticthreat/patch-2
Create salesforce-aura-objects.txt

Source: Salesforces' documentation
2022-11-22 12:12:18 +00:00
g0tmi1k
4296f91216
Merge pull request #810 from gypsydiver/wp-plugins-update
add site-editor and mail-masta to wp-plugins.fuzz.txt
2022-11-22 12:11:39 +00:00
g0tmi1k
517c44b24e
Merge pull request #808 from InTruder-Sec/master
Added more API directories for web application  enumeration
2022-11-22 12:10:51 +00:00
g0tmi1k
2ce0271683
Merge pull request #807 from righettod/feature_update_springboot
[spring-boot.txt] Add new endpoints

- https://docs.spring.io/spring-boot/docs/current/reference/html/application-properties.html#application-properties.actuator.management.server.base-path
- https://docs.spring.io/spring-boot/docs/current/reference/html/actuator.html#actuator.endpoints
2022-11-22 12:09:25 +00:00
g0tmi1k
76d436287d
Merge pull request #805 from its0x08/patch-1
chore: Add WEB-INF list

Source:
- https://gist.github.com/harisec/519dc6b45c6b594908c37d9ac19edbc3
- https://github.com/projectdiscovery/nuclei-templates/blob/master/vulnerabilities/generic/generic-j2ee-lfi.yaml
- https://github.com/ilmila/J2EEScan/blob/master/src/main/java/burp/j2ee/issues/impl/LFIModule.java
2022-11-22 12:08:32 +00:00
g0tmi1k
f2dda11292
Merge pull request #803 from vah13/patch-1
update default-passwords.csv

Source: https://redrays.io/cve-2020-6369-patch-bypass/
2022-11-22 12:06:44 +00:00
g0tmi1k
ad20e71dbc
Merge pull request #801 from righettod/feature_adobe_aem
[AdobeCQ-AEM.txt] Cleanup and enrichment.

Source: 

- https://experienceleague.adobe.com/docs/experience-manager-dispatcher/using/getting-started/security-checklist.html#restrict-access
- https://experienceleague.adobe.com/docs/experience-manager-dispatcher/using/configuring/dispatcher-configuration.html?lang=en#testing-dispatcher-security
2022-11-22 12:05:49 +00:00
g0tmi1k
56c8071b6d
Merge pull request #800 from righettod/feature_gha_check_file_slash
Add Github workflow to check for entries starting with "/".
2022-11-22 12:02:46 +00:00
g0tmi1k
2752f1bf21
Merge pull request #746 from cyberpathogen2018/patch-1
Fixed typo on line 26

Source: https://www.acunetix.com/blog/articles/a-fresh-look-on-reverse-proxy-related-attacks/
2022-11-22 12:00:42 +00:00
g0tmi1k
8d08bb324d
Merge pull request #798 from rodnt/patch-1
Spring Boot RCE involving JMX enabled

Source: https://github.com/pyn3rd/Spring-Boot-Vulnerability#0x05-spring-boot-rce-involving-jmx-enabled
2022-11-22 11:58:45 +00:00