🌐 Read in your language: 🇬🇧 English | 🇨🇳 中文 | 🇷🇺 Русский | 🇪🇸 Español | 🇯🇵 日本語 | 🇮🇷 فارسی | 🇸🇦 العربية | 🇹🇷 Türkçe | 🇩🇪 Deutsch | 🇮🇳 हिन्दी
The most comprehensive repository on GitHub, serving as a centralized, highly optimized master collection of wordlists, dictionary attack data, and advanced fuzzing payloads tailored specifically for security professionals, penetration testers, and ethical hackers.
During security assessments and penetration testing, having immediate access to well-structured, high-quality data is critical. Standard wordlists are often scattered, outdated, or filled with redundant data that slows down brute-force attacks and web fuzzing.
This repository was created to bridge that gap. It serves as an essential infrastructure component for a security tester’s workstation. By consolidating multi-purpose lists into a single, structured repository, you can quickly clone this onto any testing environment and immediately deploy targeted dictionary attacks, directory discovery, or payload injections.
The datasets in this repository are strategically categorized and optimized to maximize speed, minimize noise, and ensure high success rates during active penetration testing and ethical hacking engagements. Below is a comprehensive breakdown of the structural blueprint of this repository:
A cutting-edge collection engineered for adversarial testing, safety alignment verification, and red-teaming of modern LLMs and AI models:
- Bias & Fairness Testing: Standardized dictionaries (
gender_bias.txt,race_ethnicity_bias.txt) to audit model alignments. - Data Leakage & Privacy: Targeted payloads to simulate accidental PII retrieval and metadata exposure (
personal_data.txt). - Adversarial & Jailbreak Prompts: Historical and evolved prompt injection sets designed to bypass model boundaries and test strict alignment constraints.
Comprehensive lists structured to aggressively map out an enterprise attack surface across network, application, and infrastructure layers:
- Directory & File Enumeration: Includes high-fidelity wordlists like the curated
raftandDirBusterseries for identifying hidden web paths, system backdoors, and shell locations. - Infrastructure & Network: Subdomain enumeration lists (including Top 1M combined variants), common web extensions, service names, and customized SNMP community strings (
snmp.txt). - CMS & Environment Contexts: Highly specific endpoints for enterprise systems and Content Management Systems including comprehensive paths for WordPress plugins/themes, Drupal, Joomla, Apache, Nginx, Tomcat, and WebSphere.
Master lists focused on high-speed credential stuffing, default-access auditing, and sophisticated brute-force dictionary attacks:
- Leaked Credentials & Dumps: Optimized variations of legendary breach datasets (such as sorted
rockyoushards,myspace, and historical leaked community patterns) with or without occurrences count. - Default Access Logs: Extensive mappings of default vendor accounts, standard router passwords, CICS transaction IDs, and multi-vendor CCTV/DVR credential profiles.
- Targeted Environments: Tailored credential files structured for specific network protocols (SSH, Telnet, Database roots, and IPMI profiles).
Advanced payloads compiled to validate application-layer flaws and filter out non-exploitable edge cases:
- Server-Side Flaws: Dynamic lists targeting Local File Inclusion (LFI) optimized for Unix/Windows paths, Remote File Inclusion, and system variable overrides.
- Web Native Components: Comprehensive mappings for parameter mining (
burp-parameter-names.txt), API discovery (api-endpoints.txt), and custom PHP fuzz lists designed to break input validation filters.
Important Notice: This repository and the datasets provided herein are created strictly for educational purposes, authorized penetration testing, and security auditing.
- User Responsibility: The ultimate responsibility for the usage of these wordlists lies entirely with the end-user. The author assumes no liability and is not responsible for any misuse, unauthorized attacks, data breaches, or legal consequences caused by the utilization of these files.
- Compliance: Ensure you have explicit, written permission from the target organization or asset owner before initiating any form of security assessment, dictionary attack, or fuzzing.
By cloning or using this repository, you agree to these terms and acknowledge that your activities must strictly adhere to local and international laws regarding cyber security.
If you encounter any issues or have configuration problems, please reach out via email at Prof.Shafiei@Gmail.com. You can also report issues on GitHub.
If you find this project helpful and would like to support further development, please consider making a donation:
Maintained with Passion by Ebrahim Shafiei (EbraSha)
-
E-Mail: Prof.Shafiei@Gmail.com
-
Telegram: @ProfShafiei
