WebWordlist Recon von s0lh4ck
Builds word, username and password lists as you browse a target during a web security assessment.
Metadaten zur Erweiterung
Screenshots
Über diese Erweiterung
WebWordlist Recon is a passive recon tool for web application security assessments. Instead of running a separate crawler (which gets blocked by WAFs and JS challenges), it rides your own Firefox session: browse the target normally, and it builds three wordlists in the background.
WHAT YOU GET
- words.txt — words pulled from visible text, alt attributes, placeholders, aria-labels, meta tags and page titles.
- usernames.txt — emails found on the site, plus usernames spotted in URLs (/user/x, /profile/x, /author/x) and author meta tags.
- passwords.txt — CUPP-style mutations (leetspeak, capitalization, common suffixes, current year) built from the most frequent words and the target's domain name.
HOW IT WORKS
1. Click the toolbar icon, pick a capture scope (target domain only, or everything you visit), and click "Start capture".
2. Browse the target as you normally would during an assessment.
3. Click "Export wordlists" to save the three files wherever you choose.
PRIVACY
The extension is inactive until you explicitly start a capture session, does all processing locally, and makes no network requests of its own — nothing is ever sent anywhere.
INTENDED USE
This is a security-testing utility for security assessments only — use it exclusively against systems and web applications you own or have explicit permission to test.
WHAT YOU GET
- words.txt — words pulled from visible text, alt attributes, placeholders, aria-labels, meta tags and page titles.
- usernames.txt — emails found on the site, plus usernames spotted in URLs (/user/x, /profile/x, /author/x) and author meta tags.
- passwords.txt — CUPP-style mutations (leetspeak, capitalization, common suffixes, current year) built from the most frequent words and the target's domain name.
HOW IT WORKS
1. Click the toolbar icon, pick a capture scope (target domain only, or everything you visit), and click "Start capture".
2. Browse the target as you normally would during an assessment.
3. Click "Export wordlists" to save the three files wherever you choose.
PRIVACY
The extension is inactive until you explicitly start a capture session, does all processing locally, and makes no network requests of its own — nothing is ever sent anywhere.
INTENDED USE
This is a security-testing utility for security assessments only — use it exclusively against systems and web applications you own or have explicit permission to test.
Bewertet mit 5 von 3 Bewertern
Berechtigungen und Daten
Benötigte Berechtigungen:
- Dateien herunterladen und die Download-Chronik lesen und verändern
- Auf Browsertabs zugreifen
- Auf Ihre Daten für diverse Websites zugreifen
Datenerfassung:
- Der Entwickler sagt, dass diese Erweiterung keine Datenerhebung benötigt.
Weitere Informationen
- Add-on-Links
- Version
- 1.0.0
- Größe
- 37,64 KB
- Zuletzt aktualisiert
- vor 8 Tagen (22. Sep. 2026)
- Verwandte Kategorien
- Lizenz
- MIT-Lizenz
- Datenschutzrichtlinie
- Lesen Sie die Datenschutzrichtlinie für dieses Add-on
- Versionsgeschichte
- Zur Sammlung hinzufügen