WebWordlist Recon 作成者: s0lh4ck
Builds word, username and password lists as you browse a target during a web security assessment.
拡張機能メタデータ
スクリーンショット
この拡張機能について
WebWordlist Recon is a passive recon tool for web application security assessments. Instead of running a separate crawler (which gets blocked by WAFs and JS challenges), it rides your own Firefox session: browse the target normally, and it builds three wordlists in the background.
WHAT YOU GET
- words.txt — words pulled from visible text, alt attributes, placeholders, aria-labels, meta tags and page titles.
- usernames.txt — emails found on the site, plus usernames spotted in URLs (/user/x, /profile/x, /author/x) and author meta tags.
- passwords.txt — CUPP-style mutations (leetspeak, capitalization, common suffixes, current year) built from the most frequent words and the target's domain name.
HOW IT WORKS
1. Click the toolbar icon, pick a capture scope (target domain only, or everything you visit), and click "Start capture".
2. Browse the target as you normally would during an assessment.
3. Click "Export wordlists" to save the three files wherever you choose.
PRIVACY
The extension is inactive until you explicitly start a capture session, does all processing locally, and makes no network requests of its own — nothing is ever sent anywhere.
INTENDED USE
This is a security-testing utility for security assessments only — use it exclusively against systems and web applications you own or have explicit permission to test.
WHAT YOU GET
- words.txt — words pulled from visible text, alt attributes, placeholders, aria-labels, meta tags and page titles.
- usernames.txt — emails found on the site, plus usernames spotted in URLs (/user/x, /profile/x, /author/x) and author meta tags.
- passwords.txt — CUPP-style mutations (leetspeak, capitalization, common suffixes, current year) built from the most frequent words and the target's domain name.
HOW IT WORKS
1. Click the toolbar icon, pick a capture scope (target domain only, or everything you visit), and click "Start capture".
2. Browse the target as you normally would during an assessment.
3. Click "Export wordlists" to save the three files wherever you choose.
PRIVACY
The extension is inactive until you explicitly start a capture session, does all processing locally, and makes no network requests of its own — nothing is ever sent anywhere.
INTENDED USE
This is a security-testing utility for security assessments only — use it exclusively against systems and web applications you own or have explicit permission to test.
3 人のレビュー担当者が 5 と評価しました
権限とデータ
必要な権限:
- ファイルのダウンロードおよびブラウザーのダウンロード履歴の読み取りと変更
- ブラウザーのタブへのアクセス
- すべてのウェブサイトの保存されたデータへのアクセス
データ収集:
- 開発者によると、この拡張機能はデータ収集を必要としません。
詳しい情報
- アドオンリンク
- バージョン
- 1.0.0
- サイズ
- 37.64 KB
- 最終更新日
- 9日前 (2026年9月22日)
- 関連カテゴリー
- ライセンス
- MIT License
- プライバシーポリシー
- このアドオンのプライバシーポリシーを読む
- バージョン履歴
- コレクションへ追加