Top Related Projects
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!
Password cracking rules for Hashcat based on statistics and industry patterns
Small utilities that are useful in advanced password cracking
Crack password hashes without the fuss :cat2:
Quick Overview
The kennyn510/wpa2-wordlists repository is a collection of wordlists specifically designed for WPA2 password cracking. It provides a variety of pre-compiled dictionaries that can be used in penetration testing and security auditing of Wi-Fi networks. The wordlists are intended to be used with tools like aircrack-ng or hashcat.
Pros
- Comprehensive collection of wordlists tailored for WPA2 cracking
- Regularly updated with new and relevant password combinations
- Saves time for security professionals by providing ready-to-use dictionaries
- Includes wordlists in different formats and sizes to suit various needs
Cons
- Potential for misuse by malicious actors
- Large file sizes may require significant storage space
- Some wordlists may contain outdated or less effective password combinations
- Ethical concerns regarding the distribution of tools that can be used for unauthorized access
Getting Started
To use these wordlists:
-
Clone the repository:
git clone https://github.com/kennyn510/wpa2-wordlists.git -
Navigate to the cloned directory:
cd wpa2-wordlists -
Choose a wordlist file based on your needs.
-
Use the selected wordlist with your preferred WPA2 cracking tool. For example, with aircrack-ng:
aircrack-ng -w path/to/wordlist.txt captured_handshake.cap
Note: Ensure you have the necessary permissions and are complying with all applicable laws and regulations when using these wordlists for security testing.
Competitor Comparisons
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
Pros of SecLists
- Comprehensive collection of multiple types of lists, including passwords, usernames, URLs, and more
- Regularly updated and maintained by a large community
- Well-organized directory structure for easy navigation
Cons of SecLists
- Large repository size may be overwhelming for specific use cases
- Some lists may contain irrelevant or outdated entries
- Requires more filtering and customization for targeted applications
Code Comparison
wpa2-wordlists:
123456789
12345678
1234567890
password
SecLists:
123456
password
12345678
qwerty
123456789
Summary
SecLists is a more extensive and versatile repository, offering a wide range of lists for various security testing purposes. It benefits from regular updates and community contributions. However, its size and breadth may be excessive for users focused solely on WPA2 cracking.
wpa2-wordlists is more specialized, focusing specifically on WPA2 password lists. This makes it more straightforward for users targeting wireless network security testing. However, it may lack the diversity and regular updates found in SecLists.
The choice between these repositories depends on the specific needs of the user. For comprehensive security testing across multiple domains, SecLists is preferable. For targeted WPA2 testing, wpa2-wordlists may be more suitable.
Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!
Pros of Probable-Wordlists
- Larger and more diverse collection of wordlists
- Regularly updated with new entries
- Includes real-world leaked passwords for more realistic testing
Cons of Probable-Wordlists
- Larger file sizes may require more storage space
- Some wordlists may contain sensitive or explicit content
- More complex organization structure
Code Comparison
While both repositories primarily contain wordlist files rather than code, Probable-Wordlists includes a simple Python script for processing wordlists:
# Probable-Wordlists
with open(input_file, 'r') as f_in, open(output_file, 'w') as f_out:
for line in f_in:
f_out.write(line.lower())
wpa2-wordlists doesn't include any code, focusing solely on providing wordlist files.
Summary
Probable-Wordlists offers a more comprehensive and up-to-date collection of wordlists, making it suitable for a wider range of password testing scenarios. However, its larger size and potential for sensitive content may be drawbacks for some users. wpa2-wordlists provides a more focused set of wordlists specifically for WPA2 testing, with a simpler organization structure. The choice between the two depends on the specific needs of the user and the type of password testing being conducted.
Password cracking rules for Hashcat based on statistics and industry patterns
Pros of Hob0Rules
- More comprehensive ruleset for password cracking
- Actively maintained with recent updates
- Includes documentation and usage examples
Cons of Hob0Rules
- Larger file size, potentially slower to process
- May require more technical knowledge to implement effectively
- Not specifically tailored for WPA2 passwords
Code Comparison
wpa2-wordlists:
123456
password
12345678
qwerty
123456789
Hob0Rules:
$[0-9]$
$[0-9]{2}$
$[0-9]{3}$
$[!@#$%^&*()_+]$
$[!@#$%^&*()_+]{2}$
The wpa2-wordlists repository contains simple word lists, while Hob0Rules provides more complex rules for generating password variations. Hob0Rules offers greater flexibility and potential for discovering passwords, but may require more processing power and expertise to utilize effectively.
Both repositories serve different purposes in the password cracking ecosystem. wpa2-wordlists is more straightforward and specifically targeted at WPA2 passwords, while Hob0Rules is a more versatile tool for general password cracking across various systems and applications.
Small utilities that are useful in advanced password cracking
Pros of hashcat-utils
- More comprehensive set of utilities for password cracking and analysis
- Actively maintained with regular updates and contributions
- Supports a wide range of hash types and attack modes
Cons of hashcat-utils
- Steeper learning curve due to more complex functionality
- Requires more system resources for advanced operations
- May be overkill for simple wordlist generation tasks
Code comparison
wpa2-wordlists:
def generate_wordlist(min_length, max_length):
chars = string.ascii_letters + string.digits
for length in range(min_length, max_length + 1):
for word in itertools.product(chars, repeat=length):
yield ''.join(word)
hashcat-utils (combinator.c):
while (!feof (fp1))
{
if (fgets (line1, BUFSIZ, fp1) == NULL) continue;
line1_len = strlen (line1);
if (line1[line1_len - 1] == '\n') line1[--line1_len] = 0;
Summary
hashcat-utils offers a more robust set of tools for password cracking and analysis, with active maintenance and support for various hash types. However, it may be more complex and resource-intensive compared to wpa2-wordlists. The latter focuses primarily on wordlist generation for WPA2 cracking, making it simpler for specific use cases. The code comparison shows the difference in complexity, with wpa2-wordlists using Python for straightforward wordlist generation, while hashcat-utils employs C for more advanced operations.
Crack password hashes without the fuss :cat2:
Pros of naive-hashcat
- Provides a complete toolset for WPA/WPA2 password cracking, including hashcat integration
- Offers a user-friendly interface for managing and executing password cracking tasks
- Includes additional features like PMKID-based attacks and automated wordlist generation
Cons of naive-hashcat
- Requires more setup and dependencies compared to simple wordlist repositories
- May have a steeper learning curve for users new to password cracking tools
- Potentially more resource-intensive due to its comprehensive feature set
Code Comparison
wpa2-wordlists:
# No code available, as it's primarily a collection of wordlists
naive-hashcat:
def crack_cap(capfile, essid, wordlist):
hashcat_cmd = f"hashcat -m 2500 -a 0 {capfile} {wordlist} --potfile-disable"
subprocess.run(hashcat_cmd, shell=True)
The wpa2-wordlists repository is primarily a collection of wordlists for WPA2 password cracking, while naive-hashcat provides a more comprehensive toolset with actual code for executing password cracking tasks. The code snippet from naive-hashcat demonstrates its integration with hashcat for cracking captured handshakes.
Convert
designs to code with AI
Introducing Visual Copilot: A new AI model to turn Figma designs to high quality code using your components.
Try Visual CopilotREADME
wpa2-wordlists
A collection of passwords and wordlists commonly used for dictionary attacks against WPA2 and other targets, using tools such as aircrack-ng, hashcat, hydra, and John the Ripper.
â ï¸ For education and authorized security testing only. These wordlists are intended for testing networks and systems you own or have explicit written permission to test. Unauthorized access to networks or accounts is illegal under the Computer Fraud and Abuse Act (CFAA) in the US, the Computer Misuse Act in the UK, and equivalent laws worldwide. You are solely responsible for how you use them.
What's Inside
| Folder | Contents |
|---|---|
Wordlists/ | Large breach-derived lists, split alphabetically and gzip-compressed (A.txt.gz, B.txt.gz, â¦). Sets include Bigone2016, Crackdown2016, Insider2016, Major2016, Neo2016, Potential2016, Ransom2016, Rockyou, and Ultimate2016. |
PlainText/ | Smaller, themed lists ready to use as-is â common logins, default router passwords, languages, numeric PINs, and more. |
Scripts/ | Helper scripts for sorting and de-duplicating lists. |
Note: These lists were compiled in 2016 from public breach data. They remain effective against weak and reused passwords, but for the newest leaks you may also want to combine them with current sources like RockYou2021/2024 and SecLists.
How To Use
# Clone the repo
git clone https://github.com/kennyn510/wpa2-wordlists.git
# Pick a wordlist set and decompress it
cd wpa2-wordlists/Wordlists/Crackdown2016
gunzip *.gz
# Combine the parts into a single file
cat *.txt > full.txt
Then point your cracking tool at full.txt, for example:
# Crack a captured WPA2 handshake with aircrack-ng
aircrack-ng handshake.cap -w full.txt
# Or with hashcat (mode 22000 = WPA2)
hashcat -m 22000 -a 0 capture.hc22000 full.txt
Filtering for WPA2 (Important)
WPA2 passwords are always at least 8 characters. Any shorter entry can never be a valid WPA2 key and only wastes cracking time. Filter your list to 8+ characters before a WPA2 attack:
# Keep only passwords 8 characters or longer
awk 'length($0) >= 8' full.txt > wpa2.txt
Prep Script (recommended)
wordlist-prep.sh does the cleaning for you â point it at any wordlist (or a whole folder of .txt/.gz files) and it removes duplicates, strips Windows line endings, and keeps only valid WPA2 candidates (8â63 printable characters):
chmod +x Scripts/wordlist-prep.sh
# Clean a single list
./Scripts/wordlist-prep.sh rockyou.txt
# Clean a whole wordlist folder and write a gzipped copy
./Scripts/wordlist-prep.sh -o ultimate-clean.txt -z Wordlists/Ultimate2016/
Run ./Scripts/wordlist-prep.sh -h for all options. A pre-cleaned Ultimate2016 list is also available on the Releases page if you'd rather just download it.
Useful One-Liners for Wordlist Manipulation
Remove duplicates (memory-safe for large files)
LC_ALL=C sort -u old.txt > new.txt
The classic
awk '!(count[$0]++)'trick keeps every unique line in RAM and runs out of memory on multi-GB lists.sort -ustreams to disk and handles huge files â use it instead.
Sort by length
awk '{print length, $0}' old.txt | sort -n | cut -d " " -f2- > new.txt
Sort alphabetically and de-duplicate
LC_ALL=C sort old.txt | uniq > new.txt
Merge multiple files into one
cat file1.txt file2.txt > combined.txt
Remove all blank lines
grep -v '^[[:space:]]*$' old.txt > new.txt
Current & Maintained Sources
The lists here were compiled in 2016 and are still effective against weak and reused passwords, but they are not actively updated. For the newest data and rule sets, combine them with these maintained projects:
- SecLists â the industry-standard collection of wordlists for passwords, usernames, fuzzing, and more.
- Weakpass â large, regularly updated wordlists aggregated from recent breaches.
- hashcat rules â mutation rules (e.g.
best64.rule) that turn a small wordlist into millions of smart variations, far more efficient than a bigger raw list. - probable-wordlists â wordlists ordered by real-world frequency.
A good modern workflow is a curated list (like the cleaned release here) plus hashcat rules, rather than one enormous raw file.
Further Reading
For more on choosing and using wordlists with aircrack-ng, hashcat, and hydra, see this guide to password wordlists for Kali Linux.
License
Released under CC0 1.0 Universal (public domain). Use them however you like.
Top Related Projects
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!
Password cracking rules for Hashcat based on statistics and industry patterns
Small utilities that are useful in advanced password cracking
Crack password hashes without the fuss :cat2:
Convert
designs to code with AI
Introducing Visual Copilot: A new AI model to turn Figma designs to high quality code using your components.
Try Visual Copilot