WebWordlist Recon di s0lh4ck
Builds word, username and password lists as you browse a target during a web security assessment.
Metadati estensione
Screenshot
Informazioni sull’estensione
WebWordlist Recon is a passive recon tool for web application security assessments. Instead of running a separate crawler (which gets blocked by WAFs and JS challenges), it rides your own Firefox session: browse the target normally, and it builds three wordlists in the background.
WHAT YOU GET
- words.txt — words pulled from visible text, alt attributes, placeholders, aria-labels, meta tags and page titles.
- usernames.txt — emails found on the site, plus usernames spotted in URLs (/user/x, /profile/x, /author/x) and author meta tags.
- passwords.txt — CUPP-style mutations (leetspeak, capitalization, common suffixes, current year) built from the most frequent words and the target's domain name.
HOW IT WORKS
1. Click the toolbar icon, pick a capture scope (target domain only, or everything you visit), and click "Start capture".
2. Browse the target as you normally would during an assessment.
3. Click "Export wordlists" to save the three files wherever you choose.
PRIVACY
The extension is inactive until you explicitly start a capture session, does all processing locally, and makes no network requests of its own — nothing is ever sent anywhere.
INTENDED USE
This is a security-testing utility for security assessments only — use it exclusively against systems and web applications you own or have explicit permission to test.
WHAT YOU GET
- words.txt — words pulled from visible text, alt attributes, placeholders, aria-labels, meta tags and page titles.
- usernames.txt — emails found on the site, plus usernames spotted in URLs (/user/x, /profile/x, /author/x) and author meta tags.
- passwords.txt — CUPP-style mutations (leetspeak, capitalization, common suffixes, current year) built from the most frequent words and the target's domain name.
HOW IT WORKS
1. Click the toolbar icon, pick a capture scope (target domain only, or everything you visit), and click "Start capture".
2. Browse the target as you normally would during an assessment.
3. Click "Export wordlists" to save the three files wherever you choose.
PRIVACY
The extension is inactive until you explicitly start a capture session, does all processing locally, and makes no network requests of its own — nothing is ever sent anywhere.
INTENDED USE
This is a security-testing utility for security assessments only — use it exclusively against systems and web applications you own or have explicit permission to test.
Voto 5 da 3 revisori
Permessi e dati
Permessi obbligatori:
- Scaricare file, leggere e modificare la cronologia di download del browser
- Accedere alle schede
- Accedere ai dati di tutti i siti web
Raccolta dati:
- Lo sviluppatore dichiara che questa estensione non richiede la raccolta di dati.
Ulteriori informazioni
- Link componente aggiuntivo
- Versione
- 1.0.0
- Dimensione
- 37,64 kB
- Ultimo aggiornamento
- 8 giorni fa (22 set 2026)
- Categorie correlate
- Licenza
- Licenza MIT
- Informativa sulla privacy
- Consulta l’informativa sulla privacy per questo componente aggiuntivo
- Cronologia versioni
- Aggiungi alla raccolta