Author Topic: really good wordlists  (Read 17224 times)

0 Members and 3 Guests are viewing this topic.

Offline Super_mario666

  • Knight
  • **
  • Posts: 160
  • Cookies: 7
  • Professional Badass
    • View Profile
really good wordlists
« on: June 15, 2013, 11:32:23 pm »
does any one know were i can find a really good wordlist to use with fern wifi cracker?
The Bigger they are...The more likely you'll get your ass kicked

Offline IFailStuff

  • VIP
  • Knight
  • *
  • Posts: 338
  • Cookies: 25
  • Certified fuckup
    • View Profile
Re: really good wordlists
« Reply #1 on: June 16, 2013, 03:39:52 am »
What makes a wordlist good? good for what.

Offline techb

  • Soy Sauce Feeler
  • Global Moderator
  • King
  • *
  • Posts: 2350
  • Cookies: 345
  • Aliens do in fact wear hats.
    • View Profile
    • github
Re: really good wordlists
« Reply #2 on: June 16, 2013, 03:46:59 am »
The target dictates the wordlist.
>>>import this
-----------------------------

Offline Super_mario666

  • Knight
  • **
  • Posts: 160
  • Cookies: 7
  • Professional Badass
    • View Profile
Re: really good wordlists
« Reply #3 on: June 16, 2013, 04:06:52 am »
The target dictates the wordlist.


the target is a home router with WPA encryption( in case you haven't noticed im fairly new at this)
The Bigger they are...The more likely you'll get your ass kicked

Offline vezzy

  • Royal Highness
  • ****
  • Posts: 771
  • Cookies: 172
    • View Profile
Re: really good wordlists
« Reply #4 on: June 16, 2013, 05:40:23 am »
I'd say this is a fairly decent password list resource.
Quote from: Dippy hippy
Just brushing though. I will be semi active mainly came to find a HQ botnet, like THOR or just any p2p botnet

Offline Super_mario666

  • Knight
  • **
  • Posts: 160
  • Cookies: 7
  • Professional Badass
    • View Profile
Re: really good wordlists
« Reply #5 on: June 16, 2013, 05:58:09 am »
I'd say this is a fairly decent password list resource.


very nice +1.
The Bigger they are...The more likely you'll get your ass kicked

Offline Darkvision

  • EZ's Fluffer
  • VIP
  • Royal Highness
  • *
  • Posts: 755
  • Cookies: 149
  • Its not a bug, It's a Chilopodas.
    • View Profile
Re: really good wordlists
« Reply #6 on: June 16, 2013, 06:19:31 am »

the target is a home router with WPA encryption( in case you haven't noticed im fairly new at this)


have you even tried to figure out what kind of router? because that as well could determine that a word list will be useless. Any number of routers now have their WPA passwords randomly generated and printed on a sticker on them. no dictionary attack is going to scratch that.
The internet: where men are men, women are men, and children are FBI agents.

Ahh, EvilZone.  Where networking certification meets avian fecal matter & all is explained, for better or worse.

<Phage> I used an entrence I never use

Offline Super_mario666

  • Knight
  • **
  • Posts: 160
  • Cookies: 7
  • Professional Badass
    • View Profile
Re: really good wordlists
« Reply #7 on: June 16, 2013, 06:43:56 am »

have you even tried to figure out what kind of router? because that as well could determine that a word list will be useless. Any number of routers now have their WPA passwords randomly generated and printed on a sticker on them. no dictionary attack is going to scratch that.


the router is my neighbors so i dont know exactly what kind he has. but just in case it was what you described what would you suggest?
The Bigger they are...The more likely you'll get your ass kicked

Offline Pak_Track

  • Royal Highness
  • ****
  • Posts: 762
  • Cookies: 69
  • Paratrooper
    • View Profile
    • My Home
Re: really good wordlists
« Reply #8 on: June 16, 2013, 08:13:29 am »
i use this when it comes to using a wordlist. It has over 4.9 million passwords.

'Life is but a series of conflicts between the easy way and the right way.'
The more you know, the more you'll realize you know nothing. -Snayler
The problem with being a smart motherfucker is that sometimes the stupid motherfuckers think you're a crazy motherfucker.
dont u hate it when you offer help and the other person says yes -Pakalu Papito

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: really good wordlists
« Reply #9 on: June 16, 2013, 10:17:00 am »
Using wordlists is a for a very specific cracking. Bruteforce is the way to go most of the time, but it can takes years...
Edit: aren't you supposed to crack WPA with handshakes and all that? AFAIK you don't need to bruteforce a lot. With WPA2 it is different.
« Last Edit: June 16, 2013, 10:18:55 am by Kulverstukas »

Offline sn0w

  • Serf
  • *
  • Posts: 39
  • Cookies: 16
  • Do your best and prepare for the worst.
    • View Profile
Re: really good wordlists
« Reply #10 on: June 16, 2013, 10:20:13 am »
http://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html

This site has good collection of wordlist. Also take some to read other post on that site. We will surly be benefited. As you said you are new to this.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: really good wordlists
« Reply #11 on: June 16, 2013, 12:10:01 pm »
One thing to check is if they changed the SSID, this is often an indication that someone edited the router configuration.
If they didnt you can easily trace back the the ISP, check for their password configuration.
In certain cases ive found those to be extremely poor for example an 8 digit random generated string, which is viable to bruteforce.
Other cases use defaults of 10 char lower/upper/digits, basically your screwed unless you have some  very very powerfull GPU setup.

One thing that you might wanna do is learn how people contruct passwords.
Ive encountered many passwords and for example routers with ; 12345678
My lucky day :P
Often people do something like this ; banana
Than the router says; "minimum of 8", the person thinks "shit".
Adds a "12" so it becomes banana12.

:)
« Last Edit: June 16, 2013, 12:11:44 pm by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Darkvision

  • EZ's Fluffer
  • VIP
  • Royal Highness
  • *
  • Posts: 755
  • Cookies: 149
  • Its not a bug, It's a Chilopodas.
    • View Profile
Re: really good wordlists
« Reply #12 on: June 16, 2013, 04:02:16 pm »

the router is my neighbors so i dont know exactly what kind he has. but just in case it was what you described what would you suggest?


Well getting more information about it is always your best bet, so a program like netstumbler(if you have a non built in wireless adapter) can be very useful. For one it will still find networks that are not broadcasting. Anyway now that you are armed with the SSID, if it is a default setup and a wireless modem/router purchased from a company often they will stick to a very "easy" to spot naming convention. ie ATT 2wire(###) Now that we know that, we can look at how they configure their network passwords. 10 characters! oh but wait its not alphanumeric, its just numeric. ease to brute force crack=super easy. In essence once you hit 10 billion passwords you have either cracked the password, or learned that the user changed it. If the user changed it now you need to broaden your horizons to brute force alphanumeric, or try a dictionary attack.


Also as stated the exact encryption being used is sometimes vulnerable to other sort of attacks that can work much faster than brute forcing it.


As you have seem to yet discover, hacking is far more about knowledge than a magical button you hit to own. i would suggest reading up on security vulnerabilities on the various wireless encryption schemes, the difference between brute forcing and dictionary attacks, as well as when to use them.



The internet: where men are men, women are men, and children are FBI agents.

Ahh, EvilZone.  Where networking certification meets avian fecal matter & all is explained, for better or worse.

<Phage> I used an entrence I never use