mirror of
https://github.com/danielmiessler/SecLists.git
synced 2025-05-31 10:41:34 +00:00
593 lines
15 KiB
Plaintext
593 lines
15 KiB
Plaintext
[
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A.*_rsa\\z",
|
|
"caption": "Private SSH key",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A.*_dsa\\z",
|
|
"caption": "Private SSH key",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A.*_ed25519\\z",
|
|
"caption": "Private SSH key",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A.*_ecdsa\\z",
|
|
"caption": "Private SSH key",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "path",
|
|
"type": "regex",
|
|
"pattern": "\\.?ssh/config\\z",
|
|
"caption": "SSH configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "pem",
|
|
"caption": "Potential cryptographic private key",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "regex",
|
|
"pattern": "\\Akey(pair)?\\z",
|
|
"caption": "Potential cryptographic private key",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "pkcs12",
|
|
"caption": "Potential cryptographic key bundle",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "pfx",
|
|
"caption": "Potential cryptographic key bundle",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "p12",
|
|
"caption": "Potential cryptographic key bundle",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "asc",
|
|
"caption": "Potential cryptographic key bundle",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "otr.private_key",
|
|
"caption": "Pidgin OTR private key",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?(bash_|zsh_|z)?history\\z",
|
|
"caption": "Shell command history file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?mysql_history\\z",
|
|
"caption": "MySQL client command history file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?psql_history\\z",
|
|
"caption": "PostgreSQL client command history file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?pgpass\\z",
|
|
"caption": "PostgreSQL password file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?irb_history\\z",
|
|
"caption": "Ruby IRB console history file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "path",
|
|
"type": "regex",
|
|
"pattern": "\\.?purple\\/accounts\\.xml\\z",
|
|
"caption": "Pidgin chat client account configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "path",
|
|
"type": "regex",
|
|
"pattern": "\\.?xchat2?\\/servlist_?\\.conf\\z",
|
|
"caption": "Hexchat/XChat IRC client server list configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "path",
|
|
"type": "regex",
|
|
"pattern": "\\.?irssi\\/config\\z",
|
|
"caption": "Irssi IRC client configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "path",
|
|
"type": "regex",
|
|
"pattern": "\\.?recon-ng\\/keys\\.db\\z",
|
|
"caption": "Recon-ng web reconnaissance framework API key database",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?dbeaver-data-sources.xml\\z",
|
|
"caption": "DBeaver SQL database manager configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?muttrc\\z",
|
|
"caption": "Mutt e-mail client configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?s3cfg\\z",
|
|
"caption": "S3cmd configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "path",
|
|
"type": "regex",
|
|
"pattern": "\\.?aws/credentials\\z",
|
|
"caption": "AWS CLI credentials file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?trc\\z",
|
|
"caption": "T command-line Twitter client configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "ovpn",
|
|
"caption": "OpenVPN client configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?gitrobrc\\z",
|
|
"caption": "Well, this is awkward... Gitrob configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?(bash|zsh)rc\\z",
|
|
"caption": "Shell configuration file",
|
|
"description": "Shell configuration files might contain information such as server hostnames, passwords and API keys."
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?(bash_|zsh_)?profile\\z",
|
|
"caption": "Shell profile configuration file",
|
|
"description": "Shell configuration files might contain information such as server hostnames, passwords and API keys."
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?(bash_|zsh_)?aliases\\z",
|
|
"caption": "Shell command alias configuration file",
|
|
"description": "Shell configuration files might contain information such as server hostnames, passwords and API keys."
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "secret_token.rb",
|
|
"caption": "Ruby On Rails secret token configuration file",
|
|
"description": "If the Rails secret token is known, it can allow for remote code execution. (http://www.exploit-db.com/exploits/27527/)"
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "omniauth.rb",
|
|
"caption": "OmniAuth configuration file",
|
|
"description": "The OmniAuth configuration file might contain client application secrets."
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "carrierwave.rb",
|
|
"caption": "Carrierwave configuration file",
|
|
"description": "Can contain credentials for online storage systems such as Amazon S3 and Google Storage."
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "schema.rb",
|
|
"caption": "Ruby On Rails database schema file",
|
|
"description": "Contains information on the database schema of a Ruby On Rails application."
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "database.yml",
|
|
"caption": "Potential Ruby On Rails database configuration file",
|
|
"description": "Might contain database credentials."
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "settings.py",
|
|
"caption": "Django configuration file",
|
|
"description": "Might contain database credentials, online storage system credentials, secret keys, etc."
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A(.*)?config(\\.inc)?\\.php\\z",
|
|
"caption": "PHP configuration file",
|
|
"description": "Might contain credentials and keys."
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "kdb",
|
|
"caption": "KeePass password manager database file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "agilekeychain",
|
|
"caption": "1Password password manager database file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "keychain",
|
|
"caption": "Apple Keychain database file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "regex",
|
|
"pattern": "\\Akey(store|ring)\\z",
|
|
"caption": "GNOME Keyring database file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "log",
|
|
"caption": "Log file",
|
|
"description": "Log files might contain information such as references to secret HTTP endpoints, session IDs, user information, passwords and API keys."
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "pcap",
|
|
"caption": "Network traffic capture file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "regex",
|
|
"pattern": "\\Asql(dump)?\\z",
|
|
"caption": "SQL dump file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "gnucash",
|
|
"caption": "GnuCash database file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "backup",
|
|
"caption": "Contains word: backup",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "dump",
|
|
"caption": "Contains word: dump",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "password",
|
|
"caption": "Contains word: password",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "credential",
|
|
"caption": "Contains word: credential",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "secret",
|
|
"caption": "Contains word: secret",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "private.*key",
|
|
"caption": "Contains words: private, key",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "jenkins.plugins.publish_over_ssh.BapSshPublisherPlugin.xml",
|
|
"caption": "Jenkins publish over SSH plugin file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "credentials.xml",
|
|
"caption": "Potential Jenkins credentials file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?htpasswd\\z",
|
|
"caption": "Apache htpasswd file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A(\\.|_)?netrc\\z",
|
|
"caption": "Configuration file for auto-login process",
|
|
"description": "Might contain username and password."
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "kwallet",
|
|
"caption": "KDE Wallet Manager database file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "LocalSettings.php",
|
|
"caption": "Potential MediaWiki configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "tblk",
|
|
"caption": "Tunnelblick VPN configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "path",
|
|
"type": "regex",
|
|
"pattern": "\\.?gem/credentials\\z",
|
|
"caption": "Rubygems credentials file",
|
|
"description": "Might contain API key for a rubygems.org account."
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A*\\.pubxml(\\.user)?\\z",
|
|
"caption": "Potential MSBuild publish profile",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "Favorites.plist",
|
|
"caption": "Sequel Pro MySQL database manager bookmark file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "configuration.user.xpl",
|
|
"caption": "Little Snitch firewall configuration file",
|
|
"description": "Contains traffic rules for applications"
|
|
},
|
|
{
|
|
"part": "extension",
|
|
"type": "match",
|
|
"pattern": "dayone",
|
|
"caption": "Day One journal file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "journal.txt",
|
|
"caption": "Potential jrnl journal file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?tugboat\\z",
|
|
"caption": "Tugboat DigitalOcean management tool configuration",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?git-credentials\\z",
|
|
"caption": "git-credential-store helper credentials file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?gitconfig\\z",
|
|
"caption": "Git configuration file",
|
|
"description": null
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "knife.rb",
|
|
"caption": "Chef Knife configuration file",
|
|
"description": "Might contain references to Chef servers"
|
|
},
|
|
{
|
|
"part": "path",
|
|
"type": "regex",
|
|
"pattern": "\\.?chef/(.*)\\.pem\\z",
|
|
"caption": "Chef private key",
|
|
"description": "Can be used to authenticate against Chef servers"
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "proftpdpasswd",
|
|
"caption": "cPanel backup ProFTPd credentials file",
|
|
"description": "Contains usernames and password hashes for FTP accounts"
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "robomongo.json",
|
|
"caption": "Robomongo MongoDB manager configuration file",
|
|
"description": "Might contain credentials for MongoDB databases"
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "filezilla.xml",
|
|
"caption": "FileZilla FTP configuration file",
|
|
"description": "Might contain credentials for FTP servers"
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "recentservers.xml",
|
|
"caption": "FileZilla FTP recent servers file",
|
|
"description": "Might contain credentials for FTP servers"
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "match",
|
|
"pattern": "ventrilo_srv.ini",
|
|
"caption": "Ventrilo server configuration file",
|
|
"description": "Might contain passwords"
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?dockercfg\\z",
|
|
"caption": "Docker configuration file",
|
|
"description": "Might contain credentials for public or private Docker registries"
|
|
},
|
|
{
|
|
"part": "filename",
|
|
"type": "regex",
|
|
"pattern": "\\A\\.?npmrc\\z",
|
|
"caption": "NPM configuration file",
|
|
"description": "Might contain credentials for NPM registries"
|
|
}
|
|
]
|
|
|
|
filename:.npmrc _auth
|
|
filename:.dockercfg auth
|
|
extension:pem private
|
|
extension:ppk private
|
|
filename:id_rsa or filename:id_dsa
|
|
extension:sql mysql dump
|
|
extension:sql mysql dump password
|
|
filename:credentials aws_access_key_id
|
|
filename:.s3cfg
|
|
filename:wp-config.php
|
|
filename:.htpasswd
|
|
filename:.env DB_USERNAME NOT homestead
|
|
filename:.env MAIL_HOST=smtp.gmail.com
|
|
filename:.git-credentials
|
|
PT_TOKEN language:bash
|
|
filename:.bashrc password
|
|
filename:.bashrc mailchimp
|
|
filename:.bash_profile aws
|
|
rds.amazonaws.com password
|
|
extension:json api.forecast.io
|
|
extension:json mongolab.com
|
|
extension:yaml mongolab.com
|
|
jsforce extension:js conn.login
|
|
SF_USERNAME "salesforce"
|
|
filename:.tugboat NOT "_tugboat"
|
|
HEROKU_API_KEY language:shell
|
|
HEROKU_API_KEY language:json
|
|
filename:.netrc password
|
|
filename:_netrc password
|
|
filename:hub oauth_token
|
|
filename:robomongo.json
|
|
filename:filezilla.xml Pass
|
|
filename:recentservers.xml Pass
|
|
filename:config.json auths
|
|
filename:idea14.key
|
|
filename:config irc_pass
|
|
filename:connections.xml
|
|
filename:express.conf path:.openshift
|
|
filename:.pgpass
|
|
filename:proftpdpasswd
|
|
filename:ventrilo_srv.ini
|
|
[WFClient] Password= extension:ica
|
|
filename:server.cfg rcon password
|
|
JEKYLL_GITHUB_TOKEN
|
|
filename:.bash_history
|
|
filename:.cshrc
|
|
filename:.history
|
|
filename:.sh_history
|
|
filename:sshd_config
|
|
filename:dhcpd.conf
|