avatar
oxasploits
one zero day at a time
  • HOME
  • SERVICES
  • CATEGORIES
  • ARCHIVES
  • WORDLISTS
  • EXPLOITS
  • UPTIME
  • PRIVACY
  • ABOUT
Home Password cracking wordlists reprise
Post
Large Logo

Password cracking wordlists reprise

By Marshall Whittaker
Posted Mar 26 Updated Sep 4 1 min read

Passwords

Wordlists for Password Cracking

These wordlists are some of my favorite to use for password cracking. Generally the larger the wordlist the longer it will take to crack a password, but the higher probabilty it will be in the list. These lists are line-by-line, suitable for use with John the Ripper or OCLHashcat to name a few.

If you need help cracking hashes, you can read my walkthrough of John the Ripper.


super_wpa.lst.gz - WPA wifi wordlist.
adjective_noun_3_digits_router.lst.gz - Some routers have this naming scheme.
rockyou.lst.gz - Good medium size all around wordlist.
john.lst.gz - Shorter password list bundled with John The Ripper.
bt4-password.lst.gz - Snother medium short wordlist of common passwords.
darkweb-top100000.lst.gz - Passes in order from most used.

The Lists

All lists are gzipped to save bandwidth. Total passwords included in each file is noted to the side, and was generated with:

zcat passfile.gz | wc -l

Total all lists: 2779697215 unique passwords

adjective_noun_3_digits_router.lst.gz: 1802841920 lines 4.1G

bt4-password.lst.gz: 1652903 lines 5.2M

rockyou.lst.gz: 14344391 lines 51M

super-wpa.lst.gz: 982963903 lines 4.3G

john_password.lst.gz: 3559 lines 14K

darkweb2017-top10000.lst.gz: 9999 lines 40K

I have also compiled this into a torrent for those who want them all.

Update Jun 19 2022: Sorry folks, I had to remove one of the larger wordlists because of bandwidth and disk usage limitations.

Bitcoin Donation Address:
3Ht1soLAdcBXrxbZLDJ53vry819E3rw49d

passwords
wordlist passwords cracking aircrack-ng john thc-hydra oclhashcat password shadow
This post is licensed under CC BY 4.0 by the author.
Share
Recently Updated
  • Enumerating SUID files targeted for priv esc
  • Lock binaries in memory using vmtouch cache
  • Chipmonk with NUT to event script power outages
  • CVE-2006-3392 Webmin <1.29 pivot RCE Whitepaper
  • Jekyll minification optimization
Trending Tags
exploit vulnerabilities PoC code-injection config perl walkthrough 0day blueteam bugs


  

Further Reading

Sep 15

Password cracking wordlists update

Wordlists for Password Cracking I have updated the password wordlists section with two more, one very large list, rockyou2021.lst, and a very small list, top_100_in_order.lst for cracking rate l...

Apr 4

Cracking hashed passwords with John the Ripper

So you’ve aquired a shadow file So… you have finally rooted the server and aquired the coveted /etc/shadow file. You want to reassure your access later on. What do you do now? If installing a...

Sep 14, 2021

A shadow-utils BoF whitepaper

Background A while back an old friend had asked me if I had a chfn bug. I could see why he wanted one, I mean, a suid 0 binary on every system? Wow yeah, but sadly no, at the time I did not have o...

CVE-2019-15947 Bitcoin Core crash dumps contain wallets

Cracking hashed passwords with John the Ripper

© 2022 Marshall Whittaker. Some rights reserved.