WebWordlist Recon Autor: s0lh4ck
Builds word, username and password lists as you browse a target during a web security assessment.
Metadane rozszerzenia
Zrzuty ekranu
O tym rozszerzeniu
WebWordlist Recon is a passive recon tool for web application security assessments. Instead of running a separate crawler (which gets blocked by WAFs and JS challenges), it rides your own Firefox session: browse the target normally, and it builds three wordlists in the background.
WHAT YOU GET
- words.txt — words pulled from visible text, alt attributes, placeholders, aria-labels, meta tags and page titles.
- usernames.txt — emails found on the site, plus usernames spotted in URLs (/user/x, /profile/x, /author/x) and author meta tags.
- passwords.txt — CUPP-style mutations (leetspeak, capitalization, common suffixes, current year) built from the most frequent words and the target's domain name.
HOW IT WORKS
1. Click the toolbar icon, pick a capture scope (target domain only, or everything you visit), and click "Start capture".
2. Browse the target as you normally would during an assessment.
3. Click "Export wordlists" to save the three files wherever you choose.
PRIVACY
The extension is inactive until you explicitly start a capture session, does all processing locally, and makes no network requests of its own — nothing is ever sent anywhere.
INTENDED USE
This is a security-testing utility for security assessments only — use it exclusively against systems and web applications you own or have explicit permission to test.
WHAT YOU GET
- words.txt — words pulled from visible text, alt attributes, placeholders, aria-labels, meta tags and page titles.
- usernames.txt — emails found on the site, plus usernames spotted in URLs (/user/x, /profile/x, /author/x) and author meta tags.
- passwords.txt — CUPP-style mutations (leetspeak, capitalization, common suffixes, current year) built from the most frequent words and the target's domain name.
HOW IT WORKS
1. Click the toolbar icon, pick a capture scope (target domain only, or everything you visit), and click "Start capture".
2. Browse the target as you normally would during an assessment.
3. Click "Export wordlists" to save the three files wherever you choose.
PRIVACY
The extension is inactive until you explicitly start a capture session, does all processing locally, and makes no network requests of its own — nothing is ever sent anywhere.
INTENDED USE
This is a security-testing utility for security assessments only — use it exclusively against systems and web applications you own or have explicit permission to test.
Ocenione na 5 przez 3 recenzentów
Uprawnienia i dane
Wymagane uprawnienia:
- Pobierać pliki oraz odczytywać i modyfikować historię pobranych plików przeglądarki
- Mieć dostęp do kart przeglądarki
- Mieć dostęp do danych użytkownika na wszystkich stronach
Zbieranie danych:
- Autorzy tego rozszerzenia twierdzą, że nie wymaga ono zbierania danych.
Więcej informacji
- Odnośniki dodatku
- Wersja
- 1.0.0
- Rozmiar
- 37,64 KB
- Ostatnia aktualizacja
- 8 dni temu (22 wrz 2026)
- Powiązane kategorie
- Licencja
- Licencja MIT
- Prywatność
- Zasady ochrony prywatności tego dodatku
- Historia wersji
- Dodaj do kolekcji