Commit Graph

1243 Commits

Author SHA1 Message Date
Vaibhaw
a372e23d58 Update http-request-headers-fields-large.txt 2021-06-10 14:14:31 +05:30
CHackA0101
3be6e4e6e7 Updates
1034 - Hikvision Network Camera,admin,12345,https://www.hikvision.com/UploadFile/image/EN-user%20manual%20of%20%20network%20camera%20v3.0.0.pdf

689 - Dell Switch PowerConnect,admin,admin,https://www.192-168-0-1login.org/router/dell/switch-powerconnect/12568/

1203 - IBM Storwize V7000,superuser,passw0rd,https://www.ibm.com/docs/en/flashsystem-7x00/7.8.1?topic=problem-procedure-resetting-superuser-password

2348 - SolarWinds,admin,<BLANK>,
2021-06-09 20:49:26 -06:00
cbk914
cd20324f79 Merge branch 'danielmiessler:master' into master 2021-06-09 13:09:19 +02:00
CHackA0101
d0fba77aee Insert F5 Default passwords products
892 - F5 BIG-IP Configuration utility,admin,admin,https://support.f5.com/csp/article/K13148,
893 - F5 BIG-IP command line,root,default,https://support.f5.com/csp/article/K13148,
894 -F5 BIG-IQ Configuration utility,admin,admin,https://support.f5.com/csp/article/K13148,
895 -F5 BIG-IQ command line,root,default,,https://support.f5.com/csp/article/K13148,
896 -F5 FirePass Administrative Console,admin,admin,https://support.f5.com/csp/article/K13148,
897 -F5 FirePass Maintenance Console,maintenance,n/a,https://support.f5.com/csp/article/K13148,
2021-06-07 10:43:20 -06:00
Dominique RIGHETTO
3eeb4e5292 Add Shibboleth.sso Metadata endpoint
Source: https://wiki.shibboleth.net/confluence/display/CONCEPT/MetadataForSP
2021-06-07 15:43:03 +02:00
CHackA0101
fc2d2ff14d Update with Sonatype Nexus Default Passwords:
1568 - Sonatype Nexus Repository Manager,admin,admin123,https://help.sonatype.com/repomanager2/maven-and-other-build-tools/sbt
1569 - Sonatype Nexus Repository Manager,nexus,nexus,
2021-06-02 16:09:40 -06:00
Annihilat0r
495c8a6c3f Add NoSQL payload 2021-05-29 13:21:29 +03:00
Dominique RIGHETTO
864faed87f Add "oauth/token/info" endpoint
See https://docs.gitlab.com/ee/api/oauth2.html#retrieving-the-token-information
2021-05-28 15:44:59 +02:00
Dominique RIGHETTO
56e23b6436 Add openid endpoints and metadata
See https://connect2id.com/products/server/docs/api
2021-05-28 15:20:54 +02:00
Dominique RIGHETTO
0e471e3faf Add oauth endpoints
See https://auth0.com/docs/protocols/protocol-oauth2#endpoints
2021-05-28 15:11:32 +02:00
g0tmi1k
96f8c3f40d Merge pull request #607 from g0tmi1k/release
2021.2 Release
2021-05-25 17:51:32 +01:00
g0t mi1k
da13de867f 2021.2 Release 2021-05-25 17:50:24 +01:00
g0tmi1k
664dd4c648 Merge pull request #603 from shelld3v/patch-9
More endpoints from Assetnote wordlist

https://wordlists-cdn.assetnote.io/data/automated/httparchive_apiroutes_2021_04_28.txt
2021-05-25 17:44:52 +01:00
g0tmi1k
8c35abaa4c Merge pull request #599 from drwetter/patch-5
Add balancer for apache

https://httpd.apache.org/docs/2.4/howto/reverse_proxy.html
2021-05-25 17:36:38 +01:00
g0tmi1k
3ce65b30e3 Merge pull request #594 from righettod/master
Add security.txt at the root
2021-05-25 17:35:52 +01:00
g0tmi1k
e52d55d4ad Merge pull request #584 from Splint3r7/master
Update Ruby on Rails wordlists
2021-05-25 17:33:55 +01:00
g0tmi1k
22b96249fd Merge pull request #600 from renanhsilva/master
Update wordpress.fuzz.txt
2021-05-25 17:33:30 +01:00
g0tmi1k
44c288e17a Merge pull request #601 from shelld3v/patch-8
Better wordlist
2021-05-25 17:32:54 +01:00
g0tmi1k
23fca5f452 Merge pull request #604 from cmaruti/patch-2
Update http-request-headers-fields-large.txt
2021-05-25 17:29:24 +01:00
g0tmi1k
2a13b61382 Merge pull request #605 from hectorgrecco/patch-2
Add "cms" word to list
2021-05-25 17:29:14 +01:00
g0tmi1k
dbb1a70871 Merge pull request #606 from chacka0101/patch-3
Update default-passwords.csv

Source: https://www.seeddms.org/index.php?id=2
2021-05-25 16:58:45 +01:00
CHackA0101
2b447c7d19 Update default-passwords.csv
2240	SeedDMS		admin		admin		https://www.seeddms.org/index.php?id=2

POC:
https://demo.seeddms.org/out/out.Login.php
User ID: admin
Password: admin
2021-05-17 16:43:21 -06:00
cbk914
cb4febae37 Merge branch 'danielmiessler:master' into master 2021-05-11 16:10:42 +02:00
Hector Grecco
725eeb4a4d Add "cms" word to list 2021-05-05 10:51:29 -03:00
Cristiano Maruti
43d82277e3 Update http-request-headers-fields-large.txt 2021-05-05 15:37:04 +02:00
shelld3v
096fcd8906 More endpoints from Assetnote wordlist 2021-05-05 13:35:40 +07:00
Thanasis Mitragkas
7eab0af4e4 Add Base64 Encoded tomcat-betterdefaultpasslist 2021-05-01 20:43:44 +03:00
shelld3v
fc3902bc5d Better wordlist 2021-05-01 00:04:10 +07:00
Renan Silva
3670ebf929 Update wordpress.fuzz.txt
add the file wp-config.php
2021-04-30 02:49:01 +00:00
Dirk Wetter
94354ee231 Add balancer for apache
https://httpd.apache.org/docs/2.4/howto/reverse_proxy.html
2021-04-26 18:26:17 +02:00
Dominique RIGHETTO
4a2ab64c10 Add security.txt at the root 2021-04-15 07:58:49 +02:00
Afaq
773441aed8 Update all.txt
added adminHeader.html endpoint
2021-04-11 21:16:35 +05:00
g0tmi1k
285474cf9b Merge pull request #586 from chacka0101/patch-2
Include line 2020, Raspberrypi password default.

Source: https://www.raspberrypi.org/documentation/linux/usage/users.md
2021-04-11 06:35:28 +01:00
CHackA0101
872ccb43b0 Include line 2020, Raspberrypi password default.
2020: Raspberrypi,pi,raspberry,https://www.raspberrypi.org/documentation/linux/usage/users.md
2021-04-02 12:57:56 -06:00
Splint3r7
a5f6a19362 Update Ruby on Rails wordlists 2021-03-26 12:56:05 +05:00
g0tmi1k
7693c73c26 Merge pull request #582 from slicin/patch-1
Update wp-plugins.fuzz.txt
2021-03-23 06:44:43 +00:00
g0tmi1k
d90534cd25 Merge pull request #581 from GraoMelo/patch-1
Add all 20th century anniversary dates 1900-2020.txt
2021-03-23 06:44:06 +00:00
g0tmi1k
da6d556362 Merge pull request #579 from ernestask/wip/ernestask/london
Discovery: Fix spelling and hyphenate some words
2021-03-23 06:42:40 +00:00
g0tmi1k
34898bf63e Merge pull request #578 from seran/master
Vulnerable Vtiger plugin

https://github.com/seran/vtiger-vuln-extension
2021-03-23 06:41:44 +00:00
slicin
c3c8518831 Update wp-plugins.fuzz.txt
Adding broken-link-manager to find:
CVE-2015-9453
CVE-2015-9467
CVE-2015-9468
2021-03-19 17:12:59 -04:00
GraoMelo
33b0ba07cf Add all 20th century anniversary dates
some time ago I created a list with all the possible birthday dates of the 20th century.
and also all the anniversary dates from 2001-2020 (yes already in the 21st century, partial)

the reason this list was created, because many people use dates of living people as passwords.

the file name is: 1900-2020.txt 

insertion suggestion
SecLists/
├── Passwords
├── ── Common-Credentials

previously informed in: #567 
https://github.com/danielmiessler/SecLists/issues/567
2021-03-18 19:24:36 -03:00
Ernestas Kulik
e1d08810b3 Discovery: Fix spelling and hyphenate some words
“atleast” and “sensitive” are self-explanatory here. Hyphenation makes
things even more readable, even if a tad pedantic.

https://xkcd.com/37/
2021-03-13 23:23:27 +01:00
User
357b20bf76 vulnerable vtiger plugin 2021-03-02 23:07:19 +05:30
g0tmi1k
eeea855ac5 Merge pull request #577 from righettod/master
Add "contribute.json" file entry

https://infosec.mozilla.org/guidelines/web_security#contributejson
https://www.contributejson.org/
https://github.com/mozilla/contribute.json
2021-03-01 12:43:28 +00:00
Dominique RIGHETTO
6715ca5d96 Add "contribute.json" file entry 2021-03-01 12:36:34 +01:00
g0tmi1k
3e7f7920c9 Merge pull request #572 from Zeecka/LFI_mssql_master.mdf
Add master.mdf MSSQL path to Windows LFI

https://rastating.github.io/from-lfi-to-sql-database-backup/#locating-the-instance-on-disk
2021-03-01 05:18:32 +00:00
g0tmi1k
3f5531cde3 Merge pull request #573 from righettod/master
Add specific "render" endpoints
2021-03-01 05:18:13 +00:00
g0tmi1k
f172f8fa88 Merge pull request #575 from cmaruti/patch-1
Create versioning_metafiles.txt
2021-03-01 05:17:32 +00:00
Dominique RIGHETTO
6400f4d31e Change the url to google 2021-02-26 14:12:33 +01:00
Dominique RIGHETTO
2afcf1217c Add specific render endpoints 2021-02-21 18:55:29 +01:00