Wordlists Reference¶
[!important] Kali Locations La mayoría están en
/usr/share/wordlists/.Seclistssuele estar en/usr/share/seclists (si la tienes instalada)o/usr/share/wordlists/seclists.
1. Directory Fuzzing (Gobuster/Ferox)¶
- Standard:
/usr/share/wordlists/dirb/common.txt - Better:
/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt - Large:
/usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
2. Passwords (Cracking)¶
- The King:
/usr/share/wordlists/rockyou.txt - Top 1000:
/usr/share/seclists/Passwords/Common-Credentials/10k-most-common.txt
3. Usernames¶
- Names:
/usr/share/seclists/Usernames/Names/names.txt - Top Users:
/usr/share/seclists/Usernames/top-usernames-shortlist.txt
4. Subdomains¶
subdomains-top1million-110000.txt(en Seclists/Discovery/DNS)
5. LFI / SQLi Payloads¶
- LFI:
/usr/share/seclists/Fuzzing/LFI/LFI-Jhaddix.txt - SQLi:
/usr/share/seclists/Fuzzing/SQLi/Generic-SQLi.txt