From 6362c3e275c187d9df45f10ea85b3a5c26c08f45 Mon Sep 17 00:00:00 2001 From: PinkDev1 <5990@protonmail.com> Date: Tue, 8 Nov 2022 19:15:13 -0300 Subject: [PATCH] Added dsstorewordlist.txt --- Discovery/Web-Content/README.md | 9 + Discovery/Web-Content/dsstorewordlist.txt | 1828 +++++++++++++++++++++ 2 files changed, 1837 insertions(+) create mode 100644 Discovery/Web-Content/dsstorewordlist.txt diff --git a/Discovery/Web-Content/README.md b/Discovery/Web-Content/README.md index 2e440a263f9..1d22877a23e 100644 --- a/Discovery/Web-Content/README.md +++ b/Discovery/Web-Content/README.md @@ -35,3 +35,12 @@ This list is a combination of the following wordlists: - raft-medium-directories.txt - raft-small-directories-lowercase.txt - raft-small-directories.txt + +## dsstorewordlist.txt + +SOURCE: https://github.com/aels/subdirectories-discover + +Perfect wordlist to discover directories and files on target site with tools like ffuf. +- It was collected by parsing Alexa top-million sites for **.DS_Store** files (https://en.wikipedia.org/wiki/.DS_Store), extracting all the found files, and then extracting found file and directory names from around 300k real websites. +- Then sorted by probability and removed strings with one occurrence. +- resulted file you can download is below. Happy Hunting! diff --git a/Discovery/Web-Content/dsstorewordlist.txt b/Discovery/Web-Content/dsstorewordlist.txt new file mode 100644 index 00000000000..b6a2998c971 --- /dev/null +++ b/Discovery/Web-Content/dsstorewordlist.txt @@ -0,0 +1,1828 @@ +images +index.php +css +js +wp-content +wp-content/mysql.sql +robots.txt +assets +wp-admin +wp-includes +img +fonts +license.txt +wp-login.php +xmlrpc.php +wp-load.php +wp-blog-header.php +wp-trackback.php +wp-mail.php +wp-links-opml.php +vendor +wp-cron.php +wp-comments-post.php +wp-activate.php +wp-settings.php +wp-signup.php +wp-config-sample.php +.htaccess +wp-config.php +.git +web.config +admin +uploads +templates +sitemap.xml +app +cgi-bin +system +themes +composer.json +cache +includes +README.md +static +mix-manifest.json +files +plugins +.DS_Store +media +application +manifest.json +config.php +.well-known +composer.lock +upload +scripts +lib +public +config +pdf +test +data +modules +storage +.idea +news +blog +error_log +resources +.gitignore +docs +video +api +catalog +_notes +src +library +scss +BingSiteAuth.xml +styles +videos +package.json +inc +about +ads.txt +test.php +install +font +bootstrap +node_modules +browserconfig.xml +tools +tmp +download +build +ads +404.php +php +image +api.php +php.ini +info.php +content +ckeditor +footer.php +downloads +crossdomain.xml +common +include +icons +header.php +controllers +mobile +email +tests +classes +bundles +en +dist +sass +svg +package-lock.json +keywords +contact +Nginx-1.12_vhost.conf +links.txt +support +libs +ajax +search +jobs +wp-snapshots +template +components +cms +OneSignalSDKWorker.js +temp +loader.php +bin +OneSignalSDKUpdaterWorker.js +mojo-package.sh +phpinfo.php +database +logs +sitemap.php +maps +demo +stylesheets +style +sites +sitemap +services +login.php +html +contact.php +sitemaps +local +games +audio +WEB-INF +webfonts +gulpfile.js +routes +javascript +pages +newsletter +home +help +bfb +views +var +search.php +_wpeprivate +Templates +packages +language +icon +frontend +favicon +events +documents +web +translations +privacy +dev +console +apps +nbproject +libraries +design +ckfinder +banner +qa-theme +qa-tests +qa-src +qa-plugin +qa-lang +qa-include +qa-external-example +qa-content +qa-cache +phpunit.xml +logout.php +javascripts +init.php +theme +sports +photos +mails +log +localization +core +bitrix +banners +backup +backend +site +quotes.txt +misc +logo +lang +engine +careers +about.php +Scripts +.vscode +wp +stats +speedtest +logos +less +dashboard +app_dev.php +site.webmanifest +rss +radio +favicons +app.php +webservice +mail +lp +json +forms +db +coupons +asset +artisan +archive +translate +swal +pdfconverter +override +legal +global +front +font-awesome +elFinder-2.1.51 +yss +webpack.mix.js +transit +trailertab +textfrompc +successpages +smartSearch +singleImage.php +shop +searchtab +searchselect +searchsafe +searchprivacy +searchplus +searcheasy +searchAnonymous +products +pokemon +packagetracker +overlay +onlineforms +newsprompt +musicsearch +moviesearch +localweather +landing +install-failed-template +gamessearch +forbessearch +forbesnews +flirtywallpapers +dogs +dailysearch +cli +cheapflights +celebjunky +browserappreviews +astrology +aspnet_client +administrator +TV +RecipeSearch +Recipe +LICENSE.txt +404 +.platform +wordpress +update +sounds +index.htm +flash +es +cron +articles +.elasticbeanstalk +store +script +privacy.php +partials +m +logs-files +de +captcha +Core +wp-pass.php +server.php +red +packs +newsletters +index_arab.php +index2_arab.php +images.inc.php +emails +doc +company +blogs +archivos +LICENSE +CONTRIBUTING.md +Adapter +wp-register.php +sw.js +player +maintenance +index2.php +i +gallery +flags +calendar +avatars +PHPMailer +.ebextensions +register.php +readme.rst +readme.md +pub +online +login +features +export +errors +Thumbs.db +xml +wp-rss2.php +wp-rss.php +wp-rdf.php +wp-feed.php +wp-commentsrss2.php +wp-atom.php +widgets +website +vendors +service-worker.js +index_dillema_eng.php +index-test.php +fr +font-awesome-4.7.0 +faq.php +fancybox +css_dillema +composer.phar +composer +branding +ajax.php +terms +privacy-policy.php +old +news.php +new +mail.php +faq +cron.php +contacts +bower_components +blocks +architecture.md +Images +CONTRIBUTORS.md +widget +rss.php +protected +pricing +prepros-6.config +payment +imgs +error +conf +Resources +Front +.gitattributes +webposition +upload.js +untitled folder +stores.xml +members +marketing +layouts +languages +it +functions.php +forums +filpond.js +feed +events.js.map +es.js +contributing.md +analytics +admin.php +Source +Packages +Configuration +8A659ECD4028395F9B6BE794F6C59ECF.txt +wordfence-waf.php +welcome +view +urlrewrite.php +tpl +tinymce +skin +shortpixel.txt +settings-popup +service +s +research +promo +privacy-policy +preview +press +partner +main +jquery.js +imagenes +humans.txt +htaccess.txt +geocity +functions +feeds +editor-build +blog.php +_css +ViewerJS +.ftpquota +vqmod +training +tr +shared +setup +portfolio +photo +nginx.conf +htaccess +hr +forum +download.php +documentation +db.php +cookie +config.rb +community +app-ads.txt +admincp +ad +__MACOSX +2017 +.editorconfig +users_upload +user_guide +tracking +testing +tags +sources +source +social +robots.php +pt +profiles +private-bip.ogg +private-bip.mp3 +preeti +pdfs +partners +page.php +page +minify +media-file +iafb.json +holiday +file +facebook +error.php +docker-compose.yml +courses +class +chat +captcha.php +admin_css +about-us.php +SpryAssets +Files +Dockerfile +2016 +1 +.settings +www +testimonials +test.txt +sdk +sales +reports +projects +personal +marketplace +jquery +home.php +custom +crm +contact-us.php +art +adminer.php +admin_assets +META-INF +.env +wiki +weather +video.php +upload.php +tv +text.php +templates_c +staging +software +sitemap.xml.gz +script.js +rss_cookie.txt +public_html +profile +podcast +phpthumb +models +min +manage +index +incl +hosting.htaccess +helpers +frontend_css +form +feedback.php +feedback +fb +csv +cpresources +client +campaign +bitbucket-pipelines.yml +bg +back +auth +apple-app-site-association +amp +_js +Library +Connections +CHANGELOG.md +.apdisk +user +tsconfig.json +travel +thank-you.php +terms.php +ssl +schedule +reviews +readme.txt +promos +pro +private +plugin +pay +panel +order +nl +music +meta +licencia.txt +import +img.php +homepage +guides +guide +generator +game +feed.php +espanol +e +default +controller +checkout +applications +affiliates +account +about-us +README.txt +yarn.lock +v3 +uk +twitter +tokens +third_party +team +subscribe +statics +special +sitemap.txt +sfa +safety +ro +res +r +profile.php +post +podcasts +phpmyadmin +parking +manager +locales +live +learn +layout +jetpack-onboarding +installer +index.html___jb_bak___ +image.php +ico +head.php +framework +form.php +fontawesome +fi +favicon.gif +facilities +external +emergency +draft +development +debug.log +category.php +cart.php +careers.php +career +bower.json +beta +aws +activity +aa +_template +_cache +Public +2018 +2014 +.sass-cache +.github +.TemporaryItems +zip +wp-app.php +userfiles +updates +update.php +thumbnails +terms-of-use +teams +swf +slider +slick +sl +skins +sina +signup.php +signup +ru +rss.xml +report.php +registration +registrar +purchase +promotion +product +popup +plus28 +mwp_db +mod +menu.php +member +map.php +locations +loading.gif +landings +iphone +ios +install.php +info +importing +imgcache +history +gps +firebase-messaging-sw.js +etc +dompdf +demo.php +covid +company.php +class.phpmailer.php +chrome +ar +apply +apk +apc.php +affiliate +adm +accessibility +a +_redirects +Documents +Application.cfm +360 +2020 +2015 +2 +.project +wow +whitepapers +wc-logs +vid +v +upsell-a2.php +upsell-a1.php +upgrade-a2.php +upgrade-a1.php +uninstall_templates +ua +tour +thankyou +tags.php +swfobject.js +survey +sql +showcase +secure +samples +sample +s_code.js +reseller +report +register +redirect.php +recaptchalib.php +python +publisher +project +pl +pics +phpserver +phpmailer +phpMyAdmin +people +patterns +parents +page-data +opensearch.xml +newsletter.php +n +mp3 +monitor +module +modal +map +main.php +ma +links +l +its +international +integrations +index1.php +index.asp +highslide +grow +google +generated +fpdf +farbtastic.js +faqs.php +eyeblaster +ext +embed +docker +disclaimer.php +directory +developer +database.php +css.php +crons +connect +configuration.php +compliance +cn +cm +clientscript +clients +check.php +cba +caches +c +browser +books +book +backups +b2b +avatar +auth.php +attachments +asset-manifest.json +app.js +amazon +ads.php +_vti_pvt +_includes +PIE.htc +LiveSearchSiteAuth.xml +Documentation +2019 +.svn +.htpasswd +.env.example +webservices +webmail +webalizer +web-hosting.php +vps-hosting.php +vote +v1 +users +user-uploads +update_pack +transfer +top.php +tips +thumbs +test.xml +terms-of-service.php +technology +team.php +summer +students +story.php +start +staff +sss.php +spirit +spacer.gif +solutions +sms +small +sk +sitemap1.xml +shell +session.php +server +sendmessage.php +se +sandbox +rules_files +router.php +review +refer.php +redirect +quiz +py +prototype +proofs +production +pricing.php +presentations +players +pictures +pic +paypal +other +order.php +notfound.php +notes +mexico +menu +material +mailing +lt +log.txt +licenses +layerslider +langs +ko +jquery.min.js +job +insurance +installation +index3.php +index copy.php +images2 +ie +hu +httpdocs +helper +helpdesk +help.php +handler +graphics +gfx +game-servers.php +finance +fimages +fencing +faculty +examples +event +ess +elements +domain.php +domain +diversity +desktop_app +deportes +deploy.php +d +cz +cronjobs +corporate +copyright +contest +contactus.php +contact.htm +contact-us +config.codekit +conferences +conference +concrete +comments +coming-soon +checkout.php +cfc +cdn +caribbean +captions +canada +calendar.php +cal +bbs +backgrounds +author.php +article.php +appasset +aplicaciones +animations +android +alerts +akamai +addons +_vti_cnf +_scripts +_private +_mmServerScripts +_layouts +_inc +_assets +Sozcu_V3 +News +LICENSE_AFL.txt +Assets +Applications +.htpasswds +wp-config-local.php +wp-cli.yml +webcam +wallpapers +vsa +verify +vb +util +usc_cp.php +usage +url.txt +uploader +unsubscribe.php +ui +tst.ln +tpc +tourplanner +tos.php +tos +today +thumbnail +thumb +text.txt +testing.php +testimonials.php +temp.php +tailwind.config.js +tag +t.php +sync +subdomains +styleguide +style.scss +studyabroad +staticmap +st +sound +slopelegend +sitemgr +sitemap.htm +single.php +signin.php +signaturepics +signature +sid +share +session +services.php +send.php +school +scholarships +sc +route.planner +rollingStone +robots.txt.dist +robot.txt +roadbook +revolution +resume +responsive.css.php +reg.php +redesign +recovery +recaptcha.php +rec +react +re +quotes +questions +psych +psu-edu-assets +proxy.php +provost +print.php +price +pr +portal.php +portal +pool +policy +policies +player.swf +picture_library +php.php +php.ini.sample +phone +parts +participacion +orders +opt +openhouse +op +onboarding +ohlala +offers.php +oauth +noticiasDeLaManana-2011-05-11.xml +node +nginx.htaccess +nginx.conf.sample +nba +multicultural +moodle +mondo +model +mobile-app +mlp +military +merchant +math +masterplan +master.css.php +maru +marketing.php +manual +manifest +management +maintenance.php +main.js +mailings +mailer +magazine +login2.php +locale +local-phpinfo.php +lnvideos +living +links.php +leadership +lanacion +key.php +kes +jwplayer +jsonp.php +js2 +je +iso +ipad +ip +invoice.php +installer.php +init +information +index_files +index.cfm +include.php +iletisim.php +ic +html2pdf +hosting +hooks +hola +headers +gr +go.php +gmc +gif +gh +geo +friends +free +frameworks +fit +filemanager +extres +environment +entretiempos +english +eid +edit.php +ebay +drugs +doubleclick +domain-search-result.php +dl +developers +desktop +default.php +dashboard.php +customprofilepics +customavatars +cubs +css1 +csp +coupon +counseling +cookies +contact_us.php +connectors +confirm.php +config.codekit3 +complement.css.php +common.php +comments.php +comment +cloud_theme +click.php +ci_sessions +charts +channel +changelog.txt +ccc +category +categories +cast +canchallena +buttons +business +builder +brand +borrar_video +border-radius.htc +bk +bioinformatics +big +backEnd +b06871f281fee6b241d60582ae9369b9.ttf +awards +attractions +athletics +assessment +archivo +arcade +appspec.yml +antibot +anexos +alumni +alpregio +alpcms +affiliate-program.php +advising +advertising +admissions +admin-panel +aboutus.php +abc.php +_src +_sitespect +_resources +_partials +_img +_db_backups +_akamai +__utils +_ +Widgets.LN +Vista +Susana +Servicios.LN +RollingStone.Net +Recetas +README +Personajes +PDF +New Folder With Items +NetBoot +Mobile_Detect.php +MasterLN +Logos +LN7 +LN +LICENSE.md +KioscoLN +Jardin +HTML +Guia.LN +Fourth +ContactoOH.asp +Club.LN +COPYING.txt +Brando +674f50d287a8c48dc19ba404d20fe713.eot +503.php +500.php +3 +2021 +2013 +20110919_LN6yLNNET_bkp.zip +0.js +.user.ini +.tmb +.styleci.yml +.smileys +.qidb +.buildpath +zohoverify +zohoForm.php +yii.bat +xmas +xgame +wptest4.xml +wp-scrap +wp-json +wp-config-bak.php +wp-config-backup.php +women +widget.php +white_paper_consumers_driving_the_digital_uptake.pdf +webpack.prod.js +webpack.dev.js +webpack.common.js +webmdportal61 +webmd_health_check_do_not_delete.gif +webmd_aka_test +webmd-interviews-obama.ics +webmd-app-updates +web.config.txt +wbmd +vr +vpn +vidplayer +videoimages +video_itunes +video_for_iPhone +video_config +vgoalhi +vet +ver.php +v2 +utils +utilities +usr +usfs +useruploads +uploads.ini +upgrade +update.sh +upc +unsubscribe +ultimate +tt_init.php +tt_ads.php +tt.txt +trust +trunk +translate.php +transactions +trackad.gif +toyota +topics +tool +tms +timeline +themes_admin +thanks.php +testpage.php +testmail.php +test2.xml +test2 +test1.php +test.htm +terms-of-service +template.php +template.N4BPage.php +template.MobilePage.php +template.Content_SearchPage.php +template.Content_HomePage.php +template.Content_FullPage.php +template.Content_BasicPage.php +template.BasicPage.php +tema +t3-assets +sys +sustainability +suspended.page +support.php +success.php +subscribe.php +subs_files +stylesheet +structure +strategicplan +statistics +standard.php +stage +sspv.xml +sport +sparkle +socs +socialmedia +soccer +snippets +slideshow_fp +slides +sliders +sitemap_files.xml +sitemap2.xml +site_specific +signatures +sidebar.php +showthread.php +shizhan +setup32.exe +settings +servicios +serviceWorker.php +sensor +select2 +security +searchresults.htm +sdc +scuk +script.SiteLoadLive.php +screenshots +screens +scholars +sbm +rumors +rs-plugin +root +role_banner.mp4 +robots.txt.20120205 +robots.txt.20090320 +rn +rewards +reviews.php +retail +reseller-hosting.php +requests.php +repository +reg +referral +redirect_random_video.php +redirect_random_album.php +redirect_cs.php +readme +rd.php +random_image.php +r.php +qa +promotions +product_images +prod +processsiterequest.php +process +privacy.htm +president +pregnancy-app-updates +posts +postform.php +portraits +policy.php +police +pma +plesk-stat +playoffs2009 +player.php +play.php +platform +placeholders +pixel +pingconnection.php +ping.php +pimg +pi +php_errorlog +pg +peak +pb +paypalprocess.php +payments.php +payments +payment.php +pay.php +passport +party +pain-app-updates +package.json.sample +pac +pa +p +owl-carousel +orgs +optoutcollector.php +old_robots.txt +offlineVersion.php +offline.php +nor +news.htm +new_photo +new_events +newThreeNav +nbaguess +mysql.php +mysql +my_test +muse_manifest.xml +msgimg.php +msg1.php +msg.php +msg-xilver.php +msds +msVisionTest.php +movie +monitors +mods +modcp +mobility +mobile-app-updates +mm_menu.js +migrations +migration +memcached +melbet +medscape_holiday +medscape +medpulse +medicinenet +medias +master +marketing.txt +maintenance_pages +mac +lv +lu +lost+found +logout +llv +links.htm +lightbox +life +licensing +liberty +learnmore +lbg +law +landingpage +lander +kr +kog +kg +katalog +jscripts +jp +joggers +jadu +invoice +intranet +internalaudit +insights +init.bat +infiniti +index_inc.php +index_.php +index.jsp +index.html.old +in +img2021 +images2010 +imagecache +illustrations +ics +ice +i18n +i.php +hybrid +huputv +hupubridgedoc +htdocs +hou +hlc +history.php +hi +healthcheck.php +healthcheck +hd +hao123 +groups +grid +graduation +grad +goldenkey +goddess +goalhi +go +get_image.php +get_file.php +generic +generate_sitemap +generate_robots.cfm +general +gamespace +g +from.php +frame +fotos +formUploads +ford +food +flyers +flipbook +fileLibrary +fileAccess.php +file.php +feed.rss +features2010 +fbcanvas +fairtrade +f1 +eyewonder +extra +extensions +exports +exportcookies.php +expmatch +exec +example +evergreen +estaticos +environments +env +entrepreneurship +engine1 +enews +ems +employment +email.php +election_widget +ee +edu +editorial +editor +edit_pc +edaa +ec-landing +ec +ebook +dyprize +du +dtmcms +draft2013 +draft2011 +draft2010 +downloader +documentos +document +do_not_delete +display.ShoppingCartQuickDisplay.php +discover +disclaimer +directions +dh +devtest +deploy.sh +departments.php +departments +den +dedicated-servers.php +decom +datastore +databases +data_sample +cy +customgroupicons +cu +crossdomain.xml.20100125.pl +crossdomain.xml.20100125-2.pl +crossdomain.xml.20090917 +crossdomain.xml.20090820.pl +cron_jobs +credit +cpstyles +course +count +corporate_nl +cookiewarningtest +cookieselector.php +cookielistdata.php +contactus +consult +constants.php +connection +confirmation.php +config.js +comscore-pv.json +computing +company_test +common-js +colombia +collections +cmsAPI +cloud-hosting.php +clear.gif +class.smtp.php +check18 +chatbot-client +changecookie.php +ch-rm +ch-it +ch-fr +ch-de +cgi +cg +cfsearch.cfm +ces +certs +celebrate-modern-life +ce +catalogue +case-studies +casa +cart +career.php +campaigns +callback.php +call +cacert.pem +c2dm +budget +brochure +bridge +bob.php +board +bo +bmw +blueberry +blank.gif +bjs +bif +bi_consumer.js.mjw.20150421.textClipping +bi_consumer.js +bi_common_20091022 +bi_common_20090915 +bi_common_20090911 +bi_common_20090813 +bi_common.2015-04-21.sc +bi_common.20140527 +bi_common.20100125.pl +bi_common +bermuda +be-nl +be-fr +bc +bayern +bat +backoffice +baby-app-updates +b1 +b +autoload.php +audit +attachment.php +at +asia2009 +artsci +archives +archive.php +apns +apiprocess.php +answers3-api-test-data.xml +announcements +analyticstracking.php +analytics.txt +amp.php +amazon.php +amazon-associates-link-builder +allergy-app-updates +ai-cache +advertiser +ads_view.php +ads_realtime_view.php +ads_realtime.php +ads_fifa.php +adminlte +admin_files +adclick.php +ad_view.php +ad_preview.php +ad_antd_pro +actions +accommodation +acceptable-usage-policy.php +academics +ab +a450d92cb6be01b3b3669c18bfca7901 +_test +_skins +_schedule +_main +_images +_global +_functions +_fonts +_error +_core +_cfc +YOCPlugin-installers.zip +Video +Test.pdf +Test-ICS-Event-nostart.ics +Test +Service +Readme.txt +QBserver.php +QBhelp.php +PayPal +Music +Gruntfile.js.sample +Gruntfile.js +Gemfile.lock +Gemfile +DB +Copy of bi_common +CSS +COOP +CNAME +Articles +Archive.zip +App_Data +App +API +403.php +4 +3rdpartylicenses.txt +2025 +2022 +2012 +12 +11 +1.php +1.js +0507 +001.php +000.php +.top.menu.php +.section.php +.quarantine +.localized +.hgignore +.hg +.gitlab-ci.yml +.access.php