Reference · wordlistdual-use
Sensitive files wordlist
Exposed-file name checks (.git, .env, backups, configs). Hosted here for authorized testing.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Dual-use security content. We link to the upstream project rather than re-hosting ready-to-fire files. Use only in authorized security testing.
Tagswordlist
More references
- API endpoints wordlistwordlistCommon REST API route segments for endpoint discovery. Hosted here for authorized testing.
- Common paths wordlistwordlist~4,700 common web paths and filenames for content discovery. Hosted here for authorized testing.
- GraphQL arguments wordlistwordlistCommon GraphQL argument names for schema exploration. Hosted here for authorized testing.
- GraphQL fields wordlistwordlistCommon GraphQL field names for schema exploration. Hosted here for authorized testing.
- HTTP parameters wordlistwordlist~6,400 common HTTP parameter names for parameter discovery. Hosted here for authorized testing.
- Prototype-pollution parameters wordlistwordlistParameter names used to probe for prototype pollution. Hosted here for authorized testing.