Password lists

Entropy Calculator

Default Credentials

Default Credentials

Bruteforce with default credz:

Top20 - France

Top200

Top400

Small RockYou - 500

Rockyou

Fasttrack

WeakPass

Custom List - Tools

PassGAN

kwprocessor - generate wordlists of keyboard walks

CeWL - generate wordlist from crawling website

CeWLer - generate wordlist from crawling website

Cupp - generate wordlist from known PII

Bopscrk

GeoWordlists

LDAPWordlistHarvester

Crunch

All possible character combinations created for 5 character passwords

PsudoHash - Generates keyword-based password mutations

RSMangler - perform various manipulations on a wordlist

TheMentalist

Bash

Hashcat

Rules

Mutation

John - Improve the custom list

As we all know few password are just simple words. Many use numbers and special characters. To improve our password list we can use john the ripper. We can input our own rules, or we can just use the standard john-the-ripper rules

Remove password not compliant - Password policy

Example: We know that the password must meet the following conditions:

  1. 8 characters or longer

  2. contains special characters

  3. contains numbers

Last updated