wordlist
Collection of some common wordlists such as RDP password, user name list, ssh password wordlist for brute force. IP Cameras Default Passwords.
Top Related Projects
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
This repo contains a list of the 10,000 most common English words in order of frequency, as determined by n-gram frequency analysis of the Google's Trillion Word Corpus.
:memo: A text file containing 479k English words for all your dictionary/word-based projects e.g: auto-completion / autosuggestion
Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!
Real-world infosec wordlists, updated regularly
Quick Overview
The jeanphorn/wordlist repository is a collection of various wordlists for different purposes, primarily focused on security testing and password cracking. It includes common passwords, usernames, and other frequently used terms in multiple languages, making it a valuable resource for penetration testers, security researchers, and ethical hackers.
Pros
- Comprehensive collection of wordlists for various security testing scenarios
- Includes lists in multiple languages, enhancing its global applicability
- Regularly updated with new additions and improvements
- Well-organized directory structure for easy navigation
Cons
- Some wordlists may contain offensive or inappropriate content
- Large file sizes can make downloading and storage challenging
- Potential for misuse if not handled responsibly
- Lack of detailed documentation or usage guidelines
Getting Started
To use the wordlists from this repository:
-
Clone the repository:
git clone https://github.com/jeanphorn/wordlist.git -
Navigate to the desired wordlist directory:
cd wordlist/password -
Use the wordlists with your preferred security testing tools or scripts. For example, with John the Ripper:
john --wordlist=common_passwords.txt target_hashes.txt
Remember to use these wordlists responsibly and only for authorized security testing purposes.
Competitor Comparisons
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
Pros of SecLists
- Much larger and more comprehensive collection of wordlists
- Regularly updated and maintained by a large community
- Organized into categories for different use cases (passwords, usernames, fuzzing, etc.)
Cons of SecLists
- Can be overwhelming due to its size and numerous files
- May require more time to find specific lists or customize for particular needs
Code comparison
While both repositories primarily contain text files rather than code, here's a comparison of their directory structures:
SecLists:
SecLists/
├── Discovery/
├── Fuzzing/
├── IOCs/
├── Passwords/
├── Payloads/
├── Usernames/
└── ...
wordlist:
wordlist/
├── cn/
├── en/
└── README.md
SecLists offers a more extensive and categorized structure, while wordlist provides a simpler organization based on language.
Summary
SecLists is a more comprehensive and actively maintained repository, offering a wide range of wordlists for various security testing purposes. It's well-organized but can be overwhelming due to its size. wordlist, on the other hand, is simpler and focuses on providing basic wordlists in Chinese and English, making it easier to navigate but less extensive in its offerings.
This repo contains a list of the 10,000 most common English words in order of frequency, as determined by n-gram frequency analysis of the Google's Trillion Word Corpus.
Pros of google-10000-english
- Larger word list with 10,000 most common English words
- Words sorted by frequency of usage
- Multiple list versions (all words, short words, medium words)
Cons of google-10000-english
- Limited to English words only
- Less diverse in terms of word types and categories
- No additional language support or multilingual options
Code comparison
google-10000-english:
the
of
and
to
a
wordlist:
abandon
ability
able
about
above
Summary
google-10000-english provides a comprehensive list of the most common English words, sorted by frequency. It's ideal for projects requiring a large set of commonly used words. However, it lacks diversity in word types and is limited to English.
wordlist offers a more diverse selection of words, including various categories and potentially multiple languages. It may be better suited for projects requiring a broader range of vocabulary or multilingual support.
The choice between these repositories depends on the specific needs of your project, whether you prioritize frequency-based common words or a more diverse word selection.
:memo: A text file containing 479k English words for all your dictionary/word-based projects e.g: auto-completion / autosuggestion
Pros of english-words
- Larger word list with over 466,000 English words
- Includes multiple file formats (JSON, TXT) for easy integration
- More actively maintained with recent updates
Cons of english-words
- Lacks categorization or organization of words
- May include some non-English or uncommon words
Code comparison
english-words:
with open('words_alpha.txt', 'r') as f:
words = f.read().splitlines()
wordlist:
with open('wordlist.txt', 'r') as f:
words = f.readlines()
words = [word.strip() for word in words]
Additional notes
- english-words is more suitable for general-purpose English word lists and applications requiring a comprehensive vocabulary.
- wordlist offers a smaller, curated list that may be more appropriate for specific use cases or when a more compact word list is needed.
- Both repositories provide simple text files, making them easy to integrate into various projects and programming languages.
- english-words has a larger community and more stars on GitHub, potentially indicating broader usage and support.
- wordlist hasn't been updated recently, which may be a concern for some users looking for actively maintained resources.
Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!
Pros of Probable-Wordlists
- Larger collection of wordlists, offering more variety and options
- Includes real-world password lists from data breaches, enhancing realism
- Better organized with clear categorization and naming conventions
Cons of Probable-Wordlists
- Significantly larger file sizes, potentially requiring more storage space
- May contain sensitive or personal information from real data breaches
- More complex structure, which could be overwhelming for beginners
Code Comparison
While both repositories primarily consist of text files containing wordlists, Probable-Wordlists includes some additional scripts for processing and analyzing the lists. Here's a brief comparison of their directory structures:
Wordlist:
wordlist/
├── cn_name.txt
├── english_name.txt
└── ...
Probable-Wordlists:
Probable-Wordlists/
├── Real-Passwords/
├── Dictionary-Style/
├── Analysis-Files/
└── Tools/
Probable-Wordlists offers a more structured approach with separate directories for different types of wordlists and additional tools, while Wordlist presents a simpler, flat structure with individual text files.
Real-world infosec wordlists, updated regularly
Pros of wordlists
- Significantly larger collection of wordlists (1000+ files)
- More diverse categories, including specialized lists for various purposes
- Regularly updated with new contributions
Cons of wordlists
- Less organized structure, making it harder to find specific lists
- May contain redundant or overlapping content due to its size
- Potentially overwhelming for users looking for simple, curated lists
Code comparison
wordlist:
with open('wordlist.txt', 'r') as f:
words = f.read().splitlines()
wordlists:
cat wordlists/usernames/common-usernames-unix.txt | sort | uniq > cleaned-usernames.txt
Summary
wordlists offers a vast collection of wordlists for various purposes, making it suitable for advanced users and comprehensive security testing. However, its size and organization may be overwhelming for some users. wordlist provides a more focused and curated selection, which can be easier to navigate but may lack the breadth of wordlists. The choice between the two depends on the specific needs of the user and the complexity of their project.
Convert
designs to code with AI
Introducing Visual Copilot: A new AI model to turn Figma designs to high quality code using your components.
Try Visual CopilotREADME
Wordlist Collection
A curated collection of password wordlists, username lists, and default credentials for authorized security testing and penetration testing.
â ï¸ Legal Disclaimer: These wordlists are provided strictly for security research, authorized penetration testing, and educational purposes. Unauthorized access to computer systems is illegal. Always obtain proper authorization before testing any system.
ð Directory Structure
wordlist/
âââ README.md
âââ LICENSE
âââ .gitignore
â
âââ passwords/ # Password wordlists (one password per line)
â âââ common.txt # General weak passwords (1.3M+ entries)
â âââ common_small.txt # Top 1000+ most common weak passwords
â âââ web.txt # Web application common passwords (450+)
â âââ ssh.txt # SSH brute force passwords (79K+)
â âââ rdp.txt # RDP common passwords (209K+)
â âââ ftp.txt # FTP default/common passwords (410+)
â âââ databases.txt # Database default passwords (430+)
â âââ iot.txt # IoT/smart home/industrial default passwords (430+)
â âââ chinese_weak.txt # Chinese-context weak passwords (530+)
â
âââ usernames/ # Username lists
â âââ common.txt # General username list (82K+ entries)
â âââ admin.txt # Admin/common service account usernames (78)
â
âââ defaults/ # Default credentials (structured JSON)
â âââ ip_cameras.json # IP camera/NVR default credentials
â âââ databases.json # Database default credentials with ports
â âââ nas.json # NAS device default credentials
â âââ iot.json # IoT/router/networking default credentials
â
âââ leaked/ # Passwords from public data breaches
â âââ adobe_top100.txt # Top 100 from Adobe 2013 breach
â âââ README.md # Data source descriptions
â
âââ tools/ # Utility scripts
âââ clean.py # Wordlist cleaner (remove junk, dedupe, normalize)
âââ mangler.py # Password variant generator (leet, case, suffixes)
âââ generate_chinese.py # Chinese weak password generator
âââ merge_dedupe.sh # Merge and deduplicate wordlists
âââ wordlist_stats.py # Analyze and report wordlist statistics
ð§ Tools
clean.py - Wordlist Cleaner
Clean and validate password wordlists by removing junk data.
# Basic cleaning
python3 tools/clean.py -i dirty.txt -o clean.txt
# With length filter and control character removal
python3 tools/clean.py -i dirty.txt -o clean.txt --min-len 4 --max-len 64 --no-control
# Specify encoding
python3 tools/clean.py -i dirty.txt -o clean.txt --encoding latin-1
# Dry run (stats only)
python3 tools/clean.py -i dirty.txt -o /dev/null --dry-run
mangler.py - Password Variant Generator
Generate password variants from a base wordlist.
# Apply case + leet speak rules
python3 tools/mangler.py -i passwords/common_small.txt -o mangled.txt --rules case,leet
# Apply all rules with length limit
python3 tools/mangler.py -i passwords/common_small.txt -o mangled.txt --rules all --max-len 16
# Limit output size
python3 tools/mangler.py -i passwords/common_small.txt -o mangled.txt --rules all --limit 100000
Available rules: case, leet, numbers, special, years, reverse, prefix, all
generate_chinese.py - Chinese Password Generator
Generate Chinese-context weak passwords (pinyin, lucky numbers, names).
# Generate to default path
python3 tools/generate_chinese.py -o passwords/chinese_weak_generated.txt
# Limit output size
python3 tools/generate_chinese.py -o passwords/chinese_weak_generated.txt --limit 50000
merge_dedupe.sh - Merge & Deduplicate
Merge multiple wordlists into one sorted, deduplicated file.
# Merge multiple files
bash tools/merge_dedupe.sh -o merged.txt passwords/ssh.txt passwords/web.txt
# With length filter
bash tools/merge_dedupe.sh -o merged.txt --min-len 6 --max-len 32 passwords/*.txt
wordlist_stats.py - Wordlist Analyzer
Analyze wordlist files and show statistics.
# Analyze specific files
python3 tools/wordlist_stats.py passwords/ssh.txt passwords/web.txt
# Analyze all wordlists
python3 tools/wordlist_stats.py --all
# JSON output
python3 tools/wordlist_stats.py passwords/*.txt --json
ð Wordlist Statistics
| File | Entries | Description |
|---|---|---|
| passwords/common.txt | 1,310,522 | General weak passwords (comprehensive) |
| passwords/common_small.txt | 1,316 | Top 1000+ most common |
| passwords/ssh.txt | 79215 | SSH brute force passwords |
| passwords/rdp.txt | 209,335 | RDP common passwords |
| passwords/web.txt | 453 | Web application passwords |
| passwords/ftp.txt | 413 | FTP default/common passwords |
| passwords/databases.txt | 429 | Database default passwords |
| passwords/iot.txt | 426 | IoT/smart device passwords |
| passwords/chinese_weak.txt | 530 | Chinese-context weak passwords |
| usernames/common.txt | 82,484 | General usernames |
| usernames/admin.txt | 78 | Admin account names |
| leaked/adobe_top100.txt | 100 | Adobe 2013 breach top 100 |
ð Workflow
Quick Start
# 1. Use a pre-built wordlist directly
hydra -l admin -P passwords/web.txt target http-post-form "/login:user=^USER^&pass=^PASS^"
# 2. Generate custom variants
python3 tools/mangler.py -i passwords/common_small.txt -o my_custom.txt --rules case,leet,numbers
# 3. Merge multiple sources
bash tools/merge_dedupe.sh -o custom.txt --min-len 4 passwords/web.txt passwords/ftp.txt passwords/databases.txt
# 4. Check stats
python3 tools/wordlist_stats.py custom.txt
Adding New Wordlists
- Place new
.txtfiles in the appropriate directory (passwords/,usernames/) - Run
python3 tools/clean.py -i new_file.txt -o new_file.txtto normalize - Update this README with the new entry
ð Data Sources
Password Dictionaries
- common.txt: Curated from multiple public sources (rockyou derivatives), 1.3M+ entries
- common_small.txt: SecLists Pwdb_top-1000 + 2025-2026 breach data (NordPass, Cybernews, Specops)
- web.txt: SecLists Pwdb_top-1000 + Cybernews 2025/2026 common passwords + Paul Reynolds 2026 top 150 + lucidar.me top 299 + NordPass 2025 top 200
- ssh.txt: SecLists Pwdb_top-1000 + SecLists xato-net-10-million-usernames (common passwords) + default service credentials
- rdp.txt: RDP-specific weak passwords from original repository
- ftp.txt: SecLists Pwdb_top-1000 + FTP-specific default credentials
- databases.txt: SecLists Pwdb_top-1000 + official default credentials (MySQL, PostgreSQL, Redis, MongoDB, MSSQL, Oracle, Elasticsearch)
- iot.txt: SecLists Pwdb_top-1000 + SecLists default-passwords.csv + public device databases
- chinese_weak.txt: SecLists Pwdb_top-1000 + generated Chinese weak passwords (pinyin patterns, lucky numbers, common surnames, brand passwords, gaming passwords)
Username Lists
- common.txt: Original names list + SecLists Usernames/Names/names.txt + SecLists xato-net-10-million-usernames (top 2700+ common usernames)
- admin.txt: Common admin/service account variants
Default Credentials
- routers.json: SecLists Discovery/Web-Content/default-passwords.csv
- ip_cameras.json: SecLists + public IP camera databases
- databases.json: Official vendor documentation
- nas.json: SecLists + manufacturer defaults
- iot.json: SecLists + public IoT databases
Leaked Passwords
- adobe_top100.txt: Top 100 from the Adobe 2013 data breach (130M accounts)
ð¤ Contributing
Contributions are welcome! Please:
- Fork the repository
- Add new wordlists in the appropriate directory
- Run
python3 tools/clean.pyto normalize your additions - Run
python3 tools/wordlist_stats.py --allto verify quality - Update this README
- Submit a pull request
ð License
MIT License - see LICENSE for details.
âï¸ Responsible Use
This toolkit is designed for:
- â Authorized penetration testing
- â Security research and education
- â Password policy auditing
- â CTF competitions and training
- â Unauthorized system access
- â Any illegal activity
Top Related Projects
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
This repo contains a list of the 10,000 most common English words in order of frequency, as determined by n-gram frequency analysis of the Google's Trillion Word Corpus.
:memo: A text file containing 479k English words for all your dictionary/word-based projects e.g: auto-completion / autosuggestion
Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!
Real-world infosec wordlists, updated regularly
Convert
designs to code with AI
Introducing Visual Copilot: A new AI model to turn Figma designs to high quality code using your components.
Try Visual Copilot