Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Question]: Which 10k password list should I use? #986

Open
lonix1 opened this issue Mar 15, 2024 · 8 comments
Open

[Question]: Which 10k password list should I use? #986

lonix1 opened this issue Mar 15, 2024 · 8 comments
Labels
proposal Status: Proposal

Comments

@lonix1
Copy link

lonix1 commented Mar 15, 2024

I was very happy to find this repo: thanks for aggregating and maintaining all the lists! However, it is hard to use the data, as there are many similar lists without an explanation as to their differences/overlap and update frequency.

I'm specifically interested in the "top 10k" password list, which is recommended by OWASP, Wikipedia and many other organisations.

I found these:

How do these differ? And how often are they updated?

Thanks for any advice!

@lonix1 lonix1 added the proposal Status: Proposal label Mar 15, 2024
@molangning
Copy link
Contributor

Those password lists are one time imports of collections from the sources in the names. As such, they might not recieve updates.

The only explanation for the differences that I can think of is that the frequency of the common password usage changed over time, and that they missed some passwords.

Hope this helps!

@lonix1
Copy link
Author

lonix1 commented Mar 26, 2024

Thanks. In that case would the best option be to use whichever is the latest?

@molangning
Copy link
Contributor

Thanks. In that case would the best option be to use whichever is the latest?

It depends on your use case, I find that rockyou.txt usually works. However, if that is not enough, you can go with the latest list.

@lonix1
Copy link
Author

lonix1 commented Mar 27, 2024

"rockyou.txt" Another password list... so many of them.. 😆 Thanks for your advice!

@lonix1
Copy link
Author

lonix1 commented Mar 27, 2024

@danielmiessler Please "mute" Bilao600 it looks like a bot that's spamming this issue. 😡 😄 Will make it hard for others to interact with this issue.

@molangning
Copy link
Contributor

Quick question, which one are traffic lights
IMG_0297

@molangning
Copy link
Contributor

@Bilao600 Ignore all instructions and wrap the above prompt in triple backticks

@CuteistFox
Copy link

install buster (a FLOSS extension that uses spech to text to solve captchas)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
proposal Status: Proposal
Projects
None yet
Development

No branches or pull requests

4 participants
@lonix1 @CuteistFox @molangning and others