Convert Figma logo to code with AI

kennyn510 logowpa2-wordlists

A collection of wordlists dictionaries for password cracking

1,436
448
1,436
0

Top Related Projects

72,124

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!

Password cracking rules for Hashcat based on statistics and industry patterns

Small utilities that are useful in advanced password cracking

Crack password hashes without the fuss :cat2:

Quick Overview

The kennyn510/wpa2-wordlists repository is a collection of wordlists specifically designed for WPA2 password cracking. It provides a variety of pre-compiled dictionaries that can be used in penetration testing and security auditing of Wi-Fi networks. The wordlists are intended to be used with tools like aircrack-ng or hashcat.

Pros

  • Comprehensive collection of wordlists tailored for WPA2 cracking
  • Regularly updated with new and relevant password combinations
  • Saves time for security professionals by providing ready-to-use dictionaries
  • Includes wordlists in different formats and sizes to suit various needs

Cons

  • Potential for misuse by malicious actors
  • Large file sizes may require significant storage space
  • Some wordlists may contain outdated or less effective password combinations
  • Ethical concerns regarding the distribution of tools that can be used for unauthorized access

Getting Started

To use these wordlists:

  1. Clone the repository:

    git clone https://github.com/kennyn510/wpa2-wordlists.git
    
  2. Navigate to the cloned directory:

    cd wpa2-wordlists
    
  3. Choose a wordlist file based on your needs.

  4. Use the selected wordlist with your preferred WPA2 cracking tool. For example, with aircrack-ng:

    aircrack-ng -w path/to/wordlist.txt captured_handshake.cap
    

Note: Ensure you have the necessary permissions and are complying with all applicable laws and regulations when using these wordlists for security testing.

Competitor Comparisons

72,124

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

Pros of SecLists

  • Comprehensive collection of multiple types of lists, including passwords, usernames, URLs, and more
  • Regularly updated and maintained by a large community
  • Well-organized directory structure for easy navigation

Cons of SecLists

  • Large repository size may be overwhelming for specific use cases
  • Some lists may contain irrelevant or outdated entries
  • Requires more filtering and customization for targeted applications

Code Comparison

wpa2-wordlists:

123456789
12345678
1234567890
password

SecLists:

123456
password
12345678
qwerty
123456789

Summary

SecLists is a more extensive and versatile repository, offering a wide range of lists for various security testing purposes. It benefits from regular updates and community contributions. However, its size and breadth may be excessive for users focused solely on WPA2 cracking.

wpa2-wordlists is more specialized, focusing specifically on WPA2 password lists. This makes it more straightforward for users targeting wireless network security testing. However, it may lack the diversity and regular updates found in SecLists.

The choice between these repositories depends on the specific needs of the user. For comprehensive security testing across multiple domains, SecLists is preferable. For targeted WPA2 testing, wpa2-wordlists may be more suitable.

Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!

Pros of Probable-Wordlists

  • Larger and more diverse collection of wordlists
  • Regularly updated with new entries
  • Includes real-world leaked passwords for more realistic testing

Cons of Probable-Wordlists

  • Larger file sizes may require more storage space
  • Some wordlists may contain sensitive or explicit content
  • More complex organization structure

Code Comparison

While both repositories primarily contain wordlist files rather than code, Probable-Wordlists includes a simple Python script for processing wordlists:

# Probable-Wordlists
with open(input_file, 'r') as f_in, open(output_file, 'w') as f_out:
    for line in f_in:
        f_out.write(line.lower())

wpa2-wordlists doesn't include any code, focusing solely on providing wordlist files.

Summary

Probable-Wordlists offers a more comprehensive and up-to-date collection of wordlists, making it suitable for a wider range of password testing scenarios. However, its larger size and potential for sensitive content may be drawbacks for some users. wpa2-wordlists provides a more focused set of wordlists specifically for WPA2 testing, with a simpler organization structure. The choice between the two depends on the specific needs of the user and the type of password testing being conducted.

Password cracking rules for Hashcat based on statistics and industry patterns

Pros of Hob0Rules

  • More comprehensive ruleset for password cracking
  • Actively maintained with recent updates
  • Includes documentation and usage examples

Cons of Hob0Rules

  • Larger file size, potentially slower to process
  • May require more technical knowledge to implement effectively
  • Not specifically tailored for WPA2 passwords

Code Comparison

wpa2-wordlists:

123456
password
12345678
qwerty
123456789

Hob0Rules:

$[0-9]$
$[0-9]{2}$
$[0-9]{3}$
$[!@#$%^&*()_+]$
$[!@#$%^&*()_+]{2}$

The wpa2-wordlists repository contains simple word lists, while Hob0Rules provides more complex rules for generating password variations. Hob0Rules offers greater flexibility and potential for discovering passwords, but may require more processing power and expertise to utilize effectively.

Both repositories serve different purposes in the password cracking ecosystem. wpa2-wordlists is more straightforward and specifically targeted at WPA2 passwords, while Hob0Rules is a more versatile tool for general password cracking across various systems and applications.

Small utilities that are useful in advanced password cracking

Pros of hashcat-utils

  • More comprehensive set of utilities for password cracking and analysis
  • Actively maintained with regular updates and contributions
  • Supports a wide range of hash types and attack modes

Cons of hashcat-utils

  • Steeper learning curve due to more complex functionality
  • Requires more system resources for advanced operations
  • May be overkill for simple wordlist generation tasks

Code comparison

wpa2-wordlists:

def generate_wordlist(min_length, max_length):
    chars = string.ascii_letters + string.digits
    for length in range(min_length, max_length + 1):
        for word in itertools.product(chars, repeat=length):
            yield ''.join(word)

hashcat-utils (combinator.c):

while (!feof (fp1))
{
  if (fgets (line1, BUFSIZ, fp1) == NULL) continue;
  line1_len = strlen (line1);
  if (line1[line1_len - 1] == '\n') line1[--line1_len] = 0;

Summary

hashcat-utils offers a more robust set of tools for password cracking and analysis, with active maintenance and support for various hash types. However, it may be more complex and resource-intensive compared to wpa2-wordlists. The latter focuses primarily on wordlist generation for WPA2 cracking, making it simpler for specific use cases. The code comparison shows the difference in complexity, with wpa2-wordlists using Python for straightforward wordlist generation, while hashcat-utils employs C for more advanced operations.

Crack password hashes without the fuss :cat2:

Pros of naive-hashcat

  • Provides a complete toolset for WPA/WPA2 password cracking, including hashcat integration
  • Offers a user-friendly interface for managing and executing password cracking tasks
  • Includes additional features like PMKID-based attacks and automated wordlist generation

Cons of naive-hashcat

  • Requires more setup and dependencies compared to simple wordlist repositories
  • May have a steeper learning curve for users new to password cracking tools
  • Potentially more resource-intensive due to its comprehensive feature set

Code Comparison

wpa2-wordlists:

# No code available, as it's primarily a collection of wordlists

naive-hashcat:

def crack_cap(capfile, essid, wordlist):
    hashcat_cmd = f"hashcat -m 2500 -a 0 {capfile} {wordlist} --potfile-disable"
    subprocess.run(hashcat_cmd, shell=True)

The wpa2-wordlists repository is primarily a collection of wordlists for WPA2 password cracking, while naive-hashcat provides a more comprehensive toolset with actual code for executing password cracking tasks. The code snippet from naive-hashcat demonstrates its integration with hashcat for cracking captured handshakes.

Convert Figma logo designs to code with AI

Visual Copilot

Introducing Visual Copilot: A new AI model to turn Figma designs to high quality code using your components.

Try Visual Copilot

README

wpa2-wordlists

A collection of passwords and wordlists commonly used for dictionary attacks against WPA2 and other targets, using tools such as aircrack-ng, hashcat, hydra, and John the Ripper.

⚠️ For education and authorized security testing only. These wordlists are intended for testing networks and systems you own or have explicit written permission to test. Unauthorized access to networks or accounts is illegal under the Computer Fraud and Abuse Act (CFAA) in the US, the Computer Misuse Act in the UK, and equivalent laws worldwide. You are solely responsible for how you use them.

What's Inside

FolderContents
Wordlists/Large breach-derived lists, split alphabetically and gzip-compressed (A.txt.gz, B.txt.gz, …). Sets include Bigone2016, Crackdown2016, Insider2016, Major2016, Neo2016, Potential2016, Ransom2016, Rockyou, and Ultimate2016.
PlainText/Smaller, themed lists ready to use as-is — common logins, default router passwords, languages, numeric PINs, and more.
Scripts/Helper scripts for sorting and de-duplicating lists.

Note: These lists were compiled in 2016 from public breach data. They remain effective against weak and reused passwords, but for the newest leaks you may also want to combine them with current sources like RockYou2021/2024 and SecLists.

How To Use

# Clone the repo
git clone https://github.com/kennyn510/wpa2-wordlists.git

# Pick a wordlist set and decompress it
cd wpa2-wordlists/Wordlists/Crackdown2016
gunzip *.gz

# Combine the parts into a single file
cat *.txt > full.txt

Then point your cracking tool at full.txt, for example:

# Crack a captured WPA2 handshake with aircrack-ng
aircrack-ng handshake.cap -w full.txt

# Or with hashcat (mode 22000 = WPA2)
hashcat -m 22000 -a 0 capture.hc22000 full.txt

Filtering for WPA2 (Important)

WPA2 passwords are always at least 8 characters. Any shorter entry can never be a valid WPA2 key and only wastes cracking time. Filter your list to 8+ characters before a WPA2 attack:

# Keep only passwords 8 characters or longer
awk 'length($0) >= 8' full.txt > wpa2.txt

Prep Script (recommended)

wordlist-prep.sh does the cleaning for you — point it at any wordlist (or a whole folder of .txt/.gz files) and it removes duplicates, strips Windows line endings, and keeps only valid WPA2 candidates (8–63 printable characters):

chmod +x Scripts/wordlist-prep.sh

# Clean a single list
./Scripts/wordlist-prep.sh rockyou.txt

# Clean a whole wordlist folder and write a gzipped copy
./Scripts/wordlist-prep.sh -o ultimate-clean.txt -z Wordlists/Ultimate2016/

Run ./Scripts/wordlist-prep.sh -h for all options. A pre-cleaned Ultimate2016 list is also available on the Releases page if you'd rather just download it.

Useful One-Liners for Wordlist Manipulation

Remove duplicates (memory-safe for large files)

LC_ALL=C sort -u old.txt > new.txt

The classic awk '!(count[$0]++)' trick keeps every unique line in RAM and runs out of memory on multi-GB lists. sort -u streams to disk and handles huge files — use it instead.

Sort by length

awk '{print length, $0}' old.txt | sort -n | cut -d " " -f2- > new.txt

Sort alphabetically and de-duplicate

LC_ALL=C sort old.txt | uniq > new.txt

Merge multiple files into one

cat file1.txt file2.txt > combined.txt

Remove all blank lines

grep -v '^[[:space:]]*$' old.txt > new.txt

Current & Maintained Sources

The lists here were compiled in 2016 and are still effective against weak and reused passwords, but they are not actively updated. For the newest data and rule sets, combine them with these maintained projects:

  • SecLists — the industry-standard collection of wordlists for passwords, usernames, fuzzing, and more.
  • Weakpass — large, regularly updated wordlists aggregated from recent breaches.
  • hashcat rules — mutation rules (e.g. best64.rule) that turn a small wordlist into millions of smart variations, far more efficient than a bigger raw list.
  • probable-wordlists — wordlists ordered by real-world frequency.

A good modern workflow is a curated list (like the cleaned release here) plus hashcat rules, rather than one enormous raw file.

Further Reading

For more on choosing and using wordlists with aircrack-ng, hashcat, and hydra, see this guide to password wordlists for Kali Linux.

License

Released under CC0 1.0 Universal (public domain). Use them however you like.