556 Commits

Author SHA1 Message Date
Alexander Bridges
85cc7eeadf
Added cpanel login page
reference: https://www.webhostinghub.com/help/learn/cpanel/getting-started/how-to-login-to-cpanel
2018-10-30 01:00:31 +02:00
Alexander Bridges
b4940b0a08
Merge pull request #1 from danielmiessler/master
update
2018-10-26 11:51:35 +03:00
g0tmi1k
3327ec8b40
Merge pull request #229 from drwetter/patch-1
Correct 1 typo in typo3 login ;-)
2018-10-23 12:53:05 +01:00
g0tmi1k
f5fcb3ca9b
Merge pull request #228 from toxydose/master
Add Wordpress, Django, Flask and Shopware login pages
2018-10-23 12:51:09 +01:00
Dirk Wetter
e8b1df5f84
Correct 1 typo in typo3 login
/typo3/in is IMHO not the login.
2018-10-23 13:50:09 +02:00
Alexander Bridges
2ced567e86
Add Wordpress and Shopware login pages
Added common Wordpress and Shopware CMS's login forms.

References:
https://premium.wpmudev.org/blog/find-wordpress-login/
https://github.com/toxydose/SecLists/blob/master/Discovery/Web-Content/CMS/wordpress.fuzz.txt
https://github.com/toxydose/SecLists/blob/master/Discovery/Web-Content/CMS/shopware.txt
2018-10-23 13:46:26 +03:00
g0tmi1k
6a18428339
Merge pull request #227 from toxydose/master
Add Shopware common sensitive files wordlist.
2018-10-17 15:22:55 +01:00
Alexander Bridges
5a88be0c4f
Add Shopware common sensitive files wordlist.
Shopware is open source e-commerce software 
https://github.com/shopware/shopware 
Shopware wordlist was not presented in this directory. The file should be improved and expanded
2018-10-17 17:19:53 +03:00
g0tmi1k
42d23ebe37
Merge pull request #225 from g0tmi1k/fixes
Fixes
2018.3
2018-10-15 13:09:51 +01:00
g0tmi1k
4c09aaf6c0 Add IP address header fields
Source: https://stackoverflow.com/questions/1384410/php-getenvremote-addr-serious-side-effects
2018-10-15 13:08:28 +01:00
g0tmi1k
d68ba5f9ed Rename "_" -> "-" & found a few new homes 2018-10-15 13:08:10 +01:00
g0tmi1k
d0d7aa5a60 Sort out README 2018-10-15 13:07:39 +01:00
g0tmi1k
7efce4c385
Merge pull request #224 from s0md3v/patch-1
Hand crafted XSS payloads to bypass WAFs

Source: https://github.com/s0md3v/AwesomeXSS
2018-10-15 11:43:19 +01:00
Somdev Sangwan
cebebee4b5
Create XSS-Somdev.txt 2018-10-15 02:13:17 +05:30
g0tmi1k
11bea7627e
Merge pull request #223 from govolution/patch-3
Update telnet-betterdefaultpasslist.txt

Source: https://github.com/govolution/betterdefaultpasslist/blob/master/sources.txt
2018-10-10 11:23:52 +01:00
g0tmi1k
31775a887e
Merge pull request #222 from govolution/patch-2
Update ssh-betterdefaultpasslist.txt

Source: https://github.com/govolution/betterdefaultpasslist/blob/master/sources.txt
2018-10-10 11:23:16 +01:00
g0tmi1k
19e46c19bc
Merge pull request #221 from govolution/patch-1
Add 1 default credential

Source: https://app.vagrantup.com/brunofpereira/boxes/ubuntu-base
2018-10-10 11:22:38 +01:00
govolution
ecb24ff385
Update telnet-betterdefaultpasslist.txt
For sources please refer: https://github.com/govolution/betterdefaultpasslist/blob/master/sources.txt
2018-10-10 05:57:27 +02:00
govolution
84bd8f017a
Update ssh-betterdefaultpasslist.txt
Sources: https://github.com/govolution/betterdefaultpasslist/blob/master/sources.txt
2018-10-10 05:55:43 +02:00
govolution
7928dde3c2
Update mysql-betterdefaultpasslist.txt 2018-10-10 05:52:05 +02:00
govolution
c6017c2357
Update mysql-betterdefaultpasslist.txt 2018-10-10 05:48:03 +02:00
g0tmi1k
9588809bce
Merge pull request #220 from JensTimmerman/patch-1
add default passwords for zenitel devices

Source: https://wiki.zenitel.com/wiki/Password_(IP_Stations)
2018-10-08 14:41:00 +01:00
Jens Timmerman
c57af9dcf6
add default passwords for zenitel devices
as documented at https://wiki.zenitel.com/wiki/Password_(IP_Stations)
2018-10-08 15:39:30 +02:00
g0tmi1k
4779684635
Merge pull request #219 from kongwenbin/master
Add new word list for Content Type
2018-10-07 18:27:20 +01:00
Wen Bin
fe2a64f4a1
Add new word list
I have been using this word list for a long time. Just realised that SecLists don't have a similar list such as this, so I have decided to upload it to share with the community.
2018-10-08 00:51:57 +08:00
g0tmi1k
f8987930ef
Merge pull request #218 from s7x/master
Cleaned and added the headers from @albinowax's BurpSuite param-miner Extension

Source: 05d4da3961/resources
2018-10-05 13:40:05 +01:00
CyberSemtex
a9e9e80884 Deleted the params and functions wordlists. Merged the boring_headers and headers file together then created a version with uppercases 1st letters (including after dashes) and a full uppercase version. Every file have been sorted with -u option to delete duplicates. Hit me up if you find something wrong. 2018-10-04 23:46:58 +02:00
CyberSemtex
a2f0c2cb00 Added the wordlists from param-miner extension of BurpSuite by @albinowax 2018-10-04 23:45:21 +02:00
g0tmi1k
6b0d4132bf
Merge pull request #216 from hitericcow/patch-1
Update default-passwords.csv
2018-10-03 12:49:39 +01:00
hitericcow
3fa3a9724c
Update default-passwords.csv 2018-10-03 13:45:39 +02:00
g0tmi1k
df9c03a922
Merge pull request #213 from objectified/feature/spring-boot
added wordlist for Spring Boot (Actuator)
2018-08-24 15:01:05 +01:00
objectified
bc97ca41f5 added wordlist for Spring Boot (Actuator) 2018-08-23 20:22:01 +02:00
g0tmi1k
3bd766edd2
Merge pull request #212 from tehmoon/patch-1
Update default-passwords.csv

Source: https://business.comcast.com/help-and-support/internet/setup-manage-comcast-wifi-business-wireless-gateway/
2018-08-23 08:18:27 +01:00
tehmoon
9d28400e93
Update default-passwords.csv
Default password for `cusadmin` didn't work so I looked in the [documentation](https://business.comcast.com/help-and-support/internet/setup-manage-comcast-wifi-business-wireless-gateway/) and they suggested to try between two passwords.

The second one worked.
2018-08-22 17:11:30 -04:00
g0tmi1k
f25da401da
Merge pull request #211 from melardev/add-resolvers-txt
Resolvers file for subdomain brute force
2018.2
2018-07-26 10:40:35 +01:00
MelarDev
8c3caa414b
Resolvers file for subdomain brute force
The resolvers file is mainly used in subdomain finder tools such as amass, massdns and subbrute.
The list was taken from blechschmidt/massdns github repository. There is a larger list in the subbrute
repository, but that list is no longer maintained.
2018-07-26 10:36:52 +01:00
g0tmi1k
5d2035a074
Merge pull request #210 from g0tmi1k/fixes
Add LFISuite
2018-07-25 14:01:31 +01:00
g0tmi1k
9f73b7e81a Add LFISuite
Source: https://github.com/D35m0nd142/LFISuite
2018-07-25 13:51:06 +01:00
g0tmi1k
e708bec362
Merge pull request #209 from g0tmi1k/fixes
Improved on File-names payloads
2018-07-25 12:27:13 +01:00
g0tmi1k
58f2b4db53 Improved on Filenames
Source: https://twitter.com/h1_kenan/status/1016760864144285698

Source: https://www.google.com/?q=max+characters+filename+limit+linux
2018-07-25 12:19:35 +01:00
g0tmi1k
cd9b3c6568
Merge pull request #208 from om3rcitak/patch-1
fix typo
2018-07-23 08:08:10 +01:00
omer citak
a21520442f
fix typo 2018-07-19 00:21:04 +03:00
g0tmi1k
9c67af9639
Merge pull request #207 from govolution/master
Added tomcat & added pw to mysql list
2018-07-12 21:42:28 +01:00
govolution
c7a64549a1
Update mysql-betterdefaultpasslist.txt
added vagrant pw
2018-07-12 22:13:47 +02:00
govolution
ac8f33482f
Create tomcat-betterdefaultpasslist.txt
Thx to edoz90, added some more.
2018-07-12 22:13:06 +02:00
g0tmi1k
2e9947bb8b
Merge pull request #205 from govolution/master
Source ~ https://github.com/govolution/betterdefaultpasslist/blob/master/sources.txt
2018-07-09 07:14:34 +01:00
govolution
95dad204d0
Update ssh-betterdefaultpasslist.txt 2018-07-08 21:29:55 +02:00
govolution
ce0e15a7fd
Update windows-betterdefaultpasslist.txt 2018-07-08 21:27:58 +02:00
g0tmi1k
274c088af1
Merge pull request #204 from g0tmi1k/fixes
Fixes
2018-07-05 07:22:30 +01:00
g0tmi1k
201e2abfb5 Close #195 - Confluence administration
Source: https://confluence.atlassian.com/doc/using-apache-to-limit-access-to-the-confluence-administration-interface-216433019.html
2018-07-05 07:21:57 +01:00