
一个好用的字典对于一个做渗透行业的人来说再重要不过了。之前一直苦于没有合适的字典,现在GitHub上发现的一个非常棒的Web Pentesting Fuzz 字典项目,该项目收集的字典内容非常全面,而且项目作者也一直在更新字典内容,赶紧Get收藏!
Web Pentesting Fuzz 字典,一个就够了。
不定期更新,使用前建议git pull一下,同步更新。
20200420:
20200410:
20200406:
20200410:
20200318:
20200311:
20200221:
20200211:
20200115:
20200106:
20200104:
20191219:
(\W)过滤了很多无效的参数,如空格(){}等等,并允许-的存在,重新合并去重了一下参数字典,均放在AllParam.txt,感谢奶权师傅的反馈。20191214:
20191106:
20191026:
20191022:
20190928:
20190819:
20190811:
20190801:
20190615:
工具推荐:burpsuite,sqlmap,xssfork,Wfuzz,webdirscan
如果有什么的好字典或是建议欢迎提交issue给我。
https://github.com/TheKingOfDuck/fuzzDicts/blob/master/paramDict/parameter.txt采集自ThinkPHP,yii2,phphub,Zblog,DiscuzX,WordPress等常见PHP框架/CMS。
使用技巧:如http://127.0.0.1/1.php ,视为可疑文件,进行fuzz param 选择GET,POST AND (POST JSON) AND (GET Route) AND cookie param
https://github.com/TheKingOfDuck/easyXssPayload/blob/master/easyXssPayload.txt采集自github。
https://github.com/TheKingOfDuck/fuzzDicts/tree/master/userNameDicthttps://github.com/TheKingOfDuck/fuzzDicts/tree/master/passwordDicthttps://github.com/TheKingOfDuck/fuzzDicts/tree/master/directoryDictshttps://github.com/TheKingOfDuck/fuzzDicts/blob/master/sqlDict/sql.txthttps://github.com/TheKingOfDuck/fuzzDicts/blob/master/ssrfDicts由\xeb\xfe师傅提供。
https://github.com/TheKingOfDuck/fuzzDicts/tree/master/XXEDicts收集自百度。
https://github.com/TheKingOfDuck/fuzzDicts/tree/master/ctfDict采集自kingkaki,原先收集时百度直接下载的压缩包,没看到github链接,所以没标记来源,抱歉抱歉
https://github.com/TheKingOfDuck/fuzzDicts/tree/master/apiDict/api.txt钟馗采集的代码写得很cxk 我真弟弟。。。
https://github.com/TheKingOfDuck/fuzzDicts/tree/master/routerDicts/pass.txthttps://github.com/TheKingOfDuck/fuzzDicts/tree/master/uploadFileExtDicts采集自https://github.com/c0ny1/upload-fuzz-dic-builder
https://github.com/TheKingOfDuck/fuzzDicts/tree/master/js