SecLists 是安全测试员工作伴侣。该仓库整理了大量用于安全测试的清单集合,清单中包括弱口令,常用用户名,敏感数据特征码、模糊测试载荷等。


 
Loading

该仓库已收录但尚未编辑。项目介绍及使用教程请前往 GitHub 阅读 README


0 条讨论

登录后发表评论

关于

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

创建时间
是否国产

  修改时间

2025-08-18T14:04:20Z


语言

  • PHP53.1%
  • Python15.6%
  • Classic ASP11.7%
  • Shell7.4%
  • Perl3.9%
  • Java2.8%
  • ASP.NET2.5%
  • ColdFusion1.9%
  • HTML1.1%
  • 其他0.01%

danielmiessler 的其他开源项目

danielmiessler/Fabric

Fabric is an open-source framework for augmenting humans using AI. It provides a modular system for solving specific problems using a crowdsourced set of AI prompts that can be used anywhere.

JavaScript33.09 k
4 小时前

A curated list of the most common and most interesting robots.txt disallowed directories.

Shell1.47 k
3 年前

Parse source code directories and output list of URLs that are then sent through a proxy.

147
3 年前

Quick script to gather stats on incoming credentials and IPs for a honey listener.

Shell110
3 年前

您可能感兴趣的

Python69.28 k
4 天前

大模型Grok-1开源

Python50.4 k
1 年前

Fast web fuzzer written in Go

Go14.47 k
4 个月前

Gobuster是一款用于网站目录/文件、DNS、虚拟主机vhost暴力穷举的工具,使用Go编写

Go12.34 k
4 天前
Lissy93/web-check

🕵️‍♂️ All-in-one OSINT tool for analysing any website

TypeScript26.14 k
15 天前
peass-ng/PEASS-ng

Windows、Linux/Unix*、MacOS 提权脚本合集

C#18.14 k
18 天前
Go24.38 k
9 小时前

Open-Sora: 完全开源的高效复现类Sora视频生成方案

Python27.03 k
4 个月前
182.69 k
9 个月前
22.4 k
13 天前

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

PHP8.65 k
2 年前

John the Ripper jumbo - advanced offline password cracker, which supports hundreds of hash and cipher types, and runs on many operating systems, CPUs, GPUs, and even some FPGAs

C11.77 k
11 小时前

上传截图通过GPT生成HTML/Tailwind/JavaScript代码

Python70.74 k
22 天前

#安全#sqlmap 是一个开源的渗透测试工具,可以用来自动化的检测,利用SQL注入漏洞,获取数据库服务器的权限。它具有功能强大的检测引擎,针对各种不同类型数据库的渗透测试的功能选项,包括获取数据库中存储的数据,访问操作系统文件甚至可以通过带外数据连接的方式执行操作系统命令。

Python35.06 k
9 小时前
96.43 k
7 个月前
Python62.25 k
5 小时前
danielmiessler/Fabric

Fabric is an open-source framework for augmenting humans using AI. It provides a modular system for solving specific problems using a crowdsourced set of AI prompts that can be used anywhere.

JavaScript33.09 k
4 小时前
OWASP/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Dockerfile8.23 k
6 天前

Fast subdomains enumeration tool for penetration testers

Python10.54 k
1 年前