diff --git a/README.md b/README.md index 866807f..67c0d49 100644 --- a/README.md +++ b/README.md @@ -4,6 +4,18 @@ Wordlists I use for recon and content discovery on programs from hackerone and b # How I use these lists? +## android.txt + +This is just the command I use to launch an android VM to use with MobileSecurityFramework as Geny motion is having issues with the GPU drivers I have on Linux. + +## breakpoints.txt + +These are commands that can be run the dev tools console of Chromium based browsers. + +## burp-plugins.txt + +These are some of the plugins for Burp I have installed but does not mean I have turned on at all times. I try not to rely on plugins too much as they distract you from looking at the core application. + ## http.txt I use this as my initial discovery list. @@ -23,3 +35,19 @@ I generally use this if I find some sort of API/RPC type endpoint like /api to d I use this this after discovery API objects to try map out what actions are supported. For example say you found /api, then you found /api/account and then you run this wordlist and you find /api/account/auth + +## regex.txt + +You can use these in the burp suite search function, Logger++ or Highlight and Extract plugin. + +## xss.txt + +This is just a basic taint query I use to then trace through the application so I can easily search for "taint" and then see where it is located and which characters are escaped. + +## secrets.txt + +These were triggering WAFs too frequently so I split them out into their own file. Generally you are likely better off using Burps built in interesting files but this wordlist is nice and small. + +## *.vmoptions files + +These tune the JVM for the JRE that ships with BurpSuite. I have modified the garbage collection algorithm to use a more efficient algorithm and I have applied several graphics related tweaks. diff --git a/burp-plugins.txt b/burp-plugins.txt index 12ba31b..1d1f8c6 100644 --- a/burp-plugins.txt +++ b/burp-plugins.txt @@ -1,10 +1,7 @@ Turbo Intruder HTTP Request Smuggler -Collaborator Everywhere JWT Editor Param Miner UUID Detector JS Miner -CSRF Scanner -OAUTH Scan -InQL +OAUTH Scan \ No newline at end of file diff --git a/regex.txt b/regex.txt index 83526ec..86be1b6 100644 --- a/regex.txt +++ b/regex.txt @@ -1 +1 @@ -(api|\/api\/|\/v[1-10]\/|\/\d*\.\d*\/) +(api|\/api\/|\/v[1-10]\/|\/\d*\.\d*\/) \ No newline at end of file