Merge branch 'master' into sync

This commit is contained in:
Ignacio J. Perez Portal
2025-01-25 06:36:31 -03:00
committed by GitHub
105 changed files with 1919382 additions and 1921413 deletions
+11 -19
View File
@@ -45,8 +45,11 @@ Source: [Google's RAFT](https://code.google.com/archive/p/raft/)
## combined_words.txt
### Overview
Use for: discovering files
This list is automatically updated by a github action whenever any of the lists it's composed by is modified.
This list is a combination of the following wordlists:
- big.txt
- common.txt
- raft-large-words-lowercase.txt
@@ -56,15 +59,12 @@ This list is a combination of the following wordlists:
- raft-small-words-lowercase.txt
- raft-small-words.txt
### Usage
Use for: discovering files
### Source
This list is automatically updated by a GitHub action whenever any of the lists it's composed by is modified.
## combined_directories.txt
### Overview
Use for: discovering files and directories
This list is automatically updated by a github action whenever any of the lists it's composed by is modified.
This list is a combination of the following wordlists:
- apache.txt
- combined_words.txt
@@ -89,26 +89,18 @@ This list is automatically updated by a GitHub action whenever any of the lists
## dsstorewordlist.txt
### Overview
SOURCE: https://github.com/aels/subdirectories-discover
Perfect wordlist to discover directories and files on target site with tools like ffuf.
### Usage
Use for: discovering directories and files
### Source
Source: https://github.com/aels/subdirectories-discover
### References
- It was collected by parsing Alexa top-million sites for **.DS_Store** files (https://en.wikipedia.org/wiki/.DS_Store), extracting all the found files, and then extracting found file and directory names from around 300k real websites.
- Then sorted by probability and removed strings with one occurrence.
- resulted file you can download is below. Happy Hunting!
## vulnerability-scan_j2ee-websites_WEB-INF.txt
### Overview
Use for: discovering sensitive j2ee files exploiting a lfi
### References
References:
- https://gist.github.com/harisec/519dc6b45c6b594908c37d9ac19edbc3
- https://github.com/projectdiscovery/nuclei-templates/blob/master/vulnerabilities/generic/generic-j2ee-lfi.yaml
- https://github.com/ilmila/J2EEScan/blob/master/src/main/java/burp/j2ee/issues/impl/LFIModule.java