adamdecaf / vulnerabilities

Vulnerability teaching showcase
Other
12 stars 4 forks source link

Twitter Banned Passwords list #131

Closed adamdecaf closed 8 years ago

adamdecaf commented 8 years ago

It was mentioned over on a related repos issue list that twitter's signup page will prevent cretain passwords from being used. My initial guess is that it's because they were too commonly broken into / guessed.

Anyway, here's the list.

000000
111111
11111111
112233
121212
123123
123456
1234567
12345678
123456789
131313
232323
654321
666666
696969
777777
7777777
8675309
987654
nnnnnn
nop123
nop123
nopqrs
noteglh
npprff
npprff14
npgvba
nyoreg
nyoregb
nyrkvf
nyrwnaqen
nyrwnaqeb
nznaqn
nzngrhe
nzrevpn
naqern
naqerj
natryn
natryf
navzny
nagubal
ncbyyb
nccyrf
nefrany
neguhe
nfqstu
nfqstu
nfuyrl
nffubyr
nhthfg
nhfgva
onqobl
onvyrl
onanan
onearl
onfronyy
ongzna
orngevm
ornire
ornivf
ovtpbpx
ovtqnqql
ovtqvpx
ovtqbt
ovtgvgf
oveqvr
ovgpurf
ovgrzr
oynmre
oybaqr
oybaqrf
oybjwbo
oybjzr
obaq007
obavgn
obaavr
obbobb
obbtre
obbzre
obfgba
oenaqba
oenaql
oenirf
oenmvy
oebapb
oebapbf
ohyyqbt
ohfgre
ohggre
ohggurnq
pnyiva
pnzneb
pnzreba
pnanqn
pncgnva
pneybf
pnegre
pnfcre
puneyrf
puneyvr
purrfr
puryfrn
purfgre
puvpntb
puvpxra
pbpnpbyn
pbssrr
pbyyrtr
pbzcnd
pbzchgre
pbafhzre
pbbxvr
pbbcre
pbeirggr
pbjobl
pbjoblf
pelfgny
phzzvat
phzfubg
qnxbgn
qnyynf
qnavry
qnavryyr
qroovr
qraavf
qvnoyb
qvnzbaq
qbpgbe
qbttvr
qbycuva
qbycuvaf
qbanyq
qentba
qernzf
qevire
rntyr1
rntyrf
rqjneq
rvafgrva
rebgvp
rfgeryyn
rkgerzr
snypba
sraqre
sreenev
sveroveq
svfuvat
sybevqn
sybjre
sylref
sbbgonyy
sberire
serqql
serrqbz
shpxrq
shpxre
shpxvat
shpxzr
shpxlbh
tnaqnys
tngrjnl
tngbef
trzvav
trbetr
tvnagf
tvatre
tvmzbqb
tbyqra
tbysre
tbeqba
tertbel
thvgne
thaare
unzzre
unaanu
uneqpber
uneyrl
urngure
uryczr
uragnv
ubpxrl
ubbgref
ubearl
ubgqbt
uhagre
uhagvat
vprzna
vybirlbh
vagrearg
vjnagh
wnpxvr
wnpxfba
wnthne
wnfzvar
wnfcre
wraavsre
wrerzl
wrffvpn
wbuaal
wbuafba
wbeqna
wbfrcu
wbfuhn
whavbe
whfgva
xvyyre
xavtug
ynqvrf
ynxref
ynhera
yrngure
yrtraq
yrgzrva
yrgzrva
yvggyr
ybaqba
ybiref
znqqbt
znqvfba
znttvr
zntahz
znevar
znevcbfn
zneyobeb
znegva
zneiva
znfgre
zngevk
znggurj
znirevpx
znkjryy
zryvffn
zrzore
zreprqrf
zreyva
zvpunry
zvpuryyr
zvpxrl
zvqavtug
zvyyre
zvfgerff
zbavpn
zbaxrl
zbaxrl
zbafgre
zbetna
zbgure
zbhagnva
zhssva
zhecul
zhfgnat
anxrq
anfpne
anguna
anhtugl
app1701
arjlbex
avpubynf
avpbyr
avccyr
avccyrf
byvire
benatr
cnpxref
cnagure
cnagvrf
cnexre
cnffjbeq
cnffjbeq
cnffjbeq1
cnffjbeq12
cnffjbeq123
cngevpx
crnpurf
crnahg
crccre
cunagbz
cubravk
cynlre
cyrnfr
cbbxvr
cbefpur
cevapr
cevaprff
cevingr
checyr
chffvrf
dnmjfk
djregl
djreglhv
enoovg
enpury
enpvat
envqref
envaobj
enatre
enatref
erorppn
erqfxvaf
erqfbk
erqjvatf
evpuneq
eboreg
eboregb
ebpxrg
ebfrohq
ehaare
ehfu2112
ehffvn
fnznagun
fnzzl
fnzfba
fnaqen
fnghea
fpbbol
fpbbgre
fpbecvb
fpbecvba
fronfgvna
frperg
frkfrk
funqbj
funaaba
funirq
fvreen
fvyire
fxvccl
fynlre
fzbxrl
fabbcl
fbppre
fbcuvr
fcnaxl
fcnexl
fcvqre
fdhveg
fevavinf
fgnegerx
fgnejnef
fgrryref
fgrira
fgvpxl
fghcvq
fhpprff
fhpxvg
fhzzre
fhafuvar
fhcrezna
fhesre
fjvzzvat
flqarl
grdhvreb
gnlybe
graavf
grerfn
grfgre
grfgvat
gurzna
gubznf
guhaqre
guk1138
gvssnal
gvtref
gvttre
gbzpng
gbctha
gblbgn
genivf
gebhoyr
gehfgab1
ghpxre
ghegyr
gjvggre
havgrq
intvan
ivpgbe
ivpgbevn
ivxvat
ibbqbb
iblntre
jnygre
jneevbe
jrypbzr
jungrire
jvyyvnz
jvyyvr
jvyfba
jvaare
jvafgba
jvagre
jvmneq
knivre
kkkkkk
kkkkkkkk
lnznun
lnaxrr
lnaxrrf
lryybj
mkpioa
mkpioaz
mmmmmm
fat-tire commented 8 years ago

You're missing a step here--- twitter obfuscated the words, probably to keep children from finding bad words (and Internet blocker/filters too). The list is actually in alphabetical order ;)

adamdecaf commented 8 years ago

Original Json (for reference)

{
    "profileHoversEnabled": true,
    "permalinkOverlayEnabled": false,
    "hasKenburnEffectOnSingleImage": false,
    "fav_heart_icon": false,
    "baseFoucClass": "swift-loading",
    "bodyFoucClassNames": "swift-loading",
    "macawSwift": true,
    "assetsBasePath": "https://abs.twimg.com/a/1441217790/",
    "assetVersionKey": "2561b3",
    "environment": "production",
    "formAuthenticityToken": "c77748fd6b1936f9013ebd0d6be975720dcdd1c3",
    "loggedIn": false,
    "screenName": null,
    "fullName": null,
    "userId": null,
    "allowAdsPersonalization": true,
    "scribeBufferSize": 3,
    "pageName": "signup",
    "sectionName": "form",
    "scribeParameters": {},
    "recaptchaApiUrl": "https://www.google.com/recaptcha/api/js/recaptcha_ajax.js",
    "internalReferer": null,
    "geoEnabled": false,
    "typeaheadData": {
        "accounts": {
            "enabled": true,
            "localQueriesEnabled": false,
            "remoteQueriesEnabled": true,
            "limit": 6
        },
        "trendLocations": {
            "enabled": true
        },
        "dmConversations": {
            "enabled": false
        },
        "savedSearches": {
            "enabled": false,
            "items": []
        },
        "dmAccounts": {
            "enabled": false,
            "localQueriesEnabled": false,
            "remoteQueriesEnabled": false,
            "onlyDMable": true
        },
        "mediaTagAccounts": {
            "enabled": false,
            "localQueriesEnabled": true,
            "remoteQueriesEnabled": false,
            "onlyShowUsersWithCanMediaTag": false,
            "currentUserId": -1
        },
        "selectedUsers": {
            "enabled": false
        },
        "prefillUsers": {
            "enabled": false
        },
        "topics": {
            "enabled": true,
            "localQueriesEnabled": false,
            "remoteQueriesEnabled": true,
            "prefetchLimit": 500,
            "limit": 4
        },
        "concierge": {
            "enabled": false,
            "localQueriesEnabled": false,
            "remoteQueriesEnabled": false,
            "prefetchLimit": 500,
            "limit": 6
        },
        "recentSearches": {
            "enabled": false
        },
        "hashtags": {
            "enabled": false,
            "localQueriesEnabled": false,
            "remoteQueriesEnabled": true,
            "prefetchLimit": 500
        },
        "useIndexedDB": false,
        "showSearchAccountSocialContext": false,
        "showTypeaheadTopicSocialContext": false,
        "showDebugInfo": false,
        "useThrottle": true,
        "accountsOnTop": false,
        "remoteDebounceInterval": 300,
        "remoteThrottleInterval": 300,
        "reverseBoldingEnabled": false,
        "tweetContextEnabled": false,
        "fullNameMatchingInCompose": true,
        "topicsWithFiltersEnabled": false
    },
    "dm": {
        "participant_max": 50,
        "theme": "seamful",
        "poll_options": {
            "foreground_poll_interval": 3000,
            "burst_poll_interval": 3000,
            "burst_poll_duration": 300000,
            "max_poll_interval": 60000
        },
        "notifications": false
    },
    "whitelistedVideoUser": false,
    "pushStatePageLimit": 500000,
    "routes": {
        "profile": "/"
    },
    "pushState": true,
    "viewContainer": "#page-container",
    "dragAndDropPhotoUpload": true,
    "href": "/signup",
    "searchPathWithQuery": "/search?q=query&src=typd",
    "timelineCardsGallery": true,
    "deciders": {
        "favorite_to_like": false,
        "bulkUnfollowEnabled": true,
        "custom_timeline_curation": false,
        "disable_profile_popup": false,
        "native_notifications": true,
        "dm_max_characters": 10000,
        "dm_polling_frequency_in_seconds": 3000,
        "enable_media_tag_prefetch": true,
        "enableMacawNymizerConversionLanding": false,
        "geoStructuredLocationEnabled": true,
        "hqImageUploads": false,
        "largeHeaderImageUpload": true,
        "mqImageUploads": false,
        "partnerIdSyncEnabled": true,
        "photoSruGif": false,
        "progressive_resize_enabled": true,
        "promoted_video_logging_enabled": true,
        "pushState": true,
        "scribeActionQueue": false,
        "scribeReducedActionQueue": true,
        "smartInfiniteScroll": false,
        "useHtml5Webcam": true,
        "web_perftown_stats": true,
        "web_perftown_ttft": true,
        "web_upload_direct": true,
        "web_upload_video": false,
        "dynamicVideoAdsEnabled": true,
        "internationalShippingEnabled": true,
        "useV2EndpointsEnabled": true,
        "autoplayMediaInTimeline": true,
        "useVmapVariants": false
    },
    "experiments": {},
    "permalinkCardsGallery": false,
    "toasts_dm": false,
    "toasts_spoonbill": false,
    "toasts_timeline": false,
    "toasts_dm_poll_scale": 60,
    "uploadDomain": "upload.twitter.com",
    "promptbirdData": {
        "promptbirdEnabled": false,
        "immediateTriggers": [
            "PullToRefresh",
            "Navigate"
        ],
        "format": null
    },
    "freezeDashboard": false,
    "passwordResetAdvancedLoginForm": true,
    "skipAutoSignupDialog": true,
    "shouldReplaceSignupWithLogin": false,
    "bannedPasswords": [
        "000000",
        "111111",
        "11111111",
        "112233",
        "121212",
        "123123",
        "123456",
        "1234567",
        "12345678",
        "123456789",
        "131313",
        "232323",
        "654321",
        "666666",
        "696969",
        "777777",
        "7777777",
        "8675309",
        "987654",
        "nnnnnn",
        "nop123",
        "nop123",
        "nopqrs",
        "noteglh",
        "npprff",
        "npprff14",
        "npgvba",
        "nyoreg",
        "nyoregb",
        "nyrkvf",
        "nyrwnaqen",
        "nyrwnaqeb",
        "nznaqn",
        "nzngrhe",
        "nzrevpn",
        "naqern",
        "naqerj",
        "natryn",
        "natryf",
        "navzny",
        "nagubal",
        "ncbyyb",
        "nccyrf",
        "nefrany",
        "neguhe",
        "nfqstu",
        "nfqstu",
        "nfuyrl",
        "nffubyr",
        "nhthfg",
        "nhfgva",
        "onqobl",
        "onvyrl",
        "onanan",
        "onearl",
        "onfronyy",
        "ongzna",
        "orngevm",
        "ornire",
        "ornivf",
        "ovtpbpx",
        "ovtqnqql",
        "ovtqvpx",
        "ovtqbt",
        "ovtgvgf",
        "oveqvr",
        "ovgpurf",
        "ovgrzr",
        "oynmre",
        "oybaqr",
        "oybaqrf",
        "oybjwbo",
        "oybjzr",
        "obaq007",
        "obavgn",
        "obaavr",
        "obbobb",
        "obbtre",
        "obbzre",
        "obfgba",
        "oenaqba",
        "oenaql",
        "oenirf",
        "oenmvy",
        "oebapb",
        "oebapbf",
        "ohyyqbt",
        "ohfgre",
        "ohggre",
        "ohggurnq",
        "pnyiva",
        "pnzneb",
        "pnzreba",
        "pnanqn",
        "pncgnva",
        "pneybf",
        "pnegre",
        "pnfcre",
        "puneyrf",
        "puneyvr",
        "purrfr",
        "puryfrn",
        "purfgre",
        "puvpntb",
        "puvpxra",
        "pbpnpbyn",
        "pbssrr",
        "pbyyrtr",
        "pbzcnd",
        "pbzchgre",
        "pbafhzre",
        "pbbxvr",
        "pbbcre",
        "pbeirggr",
        "pbjobl",
        "pbjoblf",
        "pelfgny",
        "phzzvat",
        "phzfubg",
        "qnxbgn",
        "qnyynf",
        "qnavry",
        "qnavryyr",
        "qroovr",
        "qraavf",
        "qvnoyb",
        "qvnzbaq",
        "qbpgbe",
        "qbttvr",
        "qbycuva",
        "qbycuvaf",
        "qbanyq",
        "qentba",
        "qernzf",
        "qevire",
        "rntyr1",
        "rntyrf",
        "rqjneq",
        "rvafgrva",
        "rebgvp",
        "rfgeryyn",
        "rkgerzr",
        "snypba",
        "sraqre",
        "sreenev",
        "sveroveq",
        "svfuvat",
        "sybevqn",
        "sybjre",
        "sylref",
        "sbbgonyy",
        "sberire",
        "serqql",
        "serrqbz",
        "shpxrq",
        "shpxre",
        "shpxvat",
        "shpxzr",
        "shpxlbh",
        "tnaqnys",
        "tngrjnl",
        "tngbef",
        "trzvav",
        "trbetr",
        "tvnagf",
        "tvatre",
        "tvmzbqb",
        "tbyqra",
        "tbysre",
        "tbeqba",
        "tertbel",
        "thvgne",
        "thaare",
        "unzzre",
        "unaanu",
        "uneqpber",
        "uneyrl",
        "urngure",
        "uryczr",
        "uragnv",
        "ubpxrl",
        "ubbgref",
        "ubearl",
        "ubgqbt",
        "uhagre",
        "uhagvat",
        "vprzna",
        "vybirlbh",
        "vagrearg",
        "vjnagh",
        "wnpxvr",
        "wnpxfba",
        "wnthne",
        "wnfzvar",
        "wnfcre",
        "wraavsre",
        "wrerzl",
        "wrffvpn",
        "wbuaal",
        "wbuafba",
        "wbeqna",
        "wbfrcu",
        "wbfuhn",
        "whavbe",
        "whfgva",
        "xvyyre",
        "xavtug",
        "ynqvrf",
        "ynxref",
        "ynhera",
        "yrngure",
        "yrtraq",
        "yrgzrva",
        "yrgzrva",
        "yvggyr",
        "ybaqba",
        "ybiref",
        "znqqbt",
        "znqvfba",
        "znttvr",
        "zntahz",
        "znevar",
        "znevcbfn",
        "zneyobeb",
        "znegva",
        "zneiva",
        "znfgre",
        "zngevk",
        "znggurj",
        "znirevpx",
        "znkjryy",
        "zryvffn",
        "zrzore",
        "zreprqrf",
        "zreyva",
        "zvpunry",
        "zvpuryyr",
        "zvpxrl",
        "zvqavtug",
        "zvyyre",
        "zvfgerff",
        "zbavpn",
        "zbaxrl",
        "zbaxrl",
        "zbafgre",
        "zbetna",
        "zbgure",
        "zbhagnva",
        "zhssva",
        "zhecul",
        "zhfgnat",
        "anxrq",
        "anfpne",
        "anguna",
        "anhtugl",
        "app1701",
        "arjlbex",
        "avpubynf",
        "avpbyr",
        "avccyr",
        "avccyrf",
        "byvire",
        "benatr",
        "cnpxref",
        "cnagure",
        "cnagvrf",
        "cnexre",
        "cnffjbeq",
        "cnffjbeq",
        "cnffjbeq1",
        "cnffjbeq12",
        "cnffjbeq123",
        "cngevpx",
        "crnpurf",
        "crnahg",
        "crccre",
        "cunagbz",
        "cubravk",
        "cynlre",
        "cyrnfr",
        "cbbxvr",
        "cbefpur",
        "cevapr",
        "cevaprff",
        "cevingr",
        "checyr",
        "chffvrf",
        "dnmjfk",
        "djregl",
        "djreglhv",
        "enoovg",
        "enpury",
        "enpvat",
        "envqref",
        "envaobj",
        "enatre",
        "enatref",
        "erorppn",
        "erqfxvaf",
        "erqfbk",
        "erqjvatf",
        "evpuneq",
        "eboreg",
        "eboregb",
        "ebpxrg",
        "ebfrohq",
        "ehaare",
        "ehfu2112",
        "ehffvn",
        "fnznagun",
        "fnzzl",
        "fnzfba",
        "fnaqen",
        "fnghea",
        "fpbbol",
        "fpbbgre",
        "fpbecvb",
        "fpbecvba",
        "fronfgvna",
        "frperg",
        "frkfrk",
        "funqbj",
        "funaaba",
        "funirq",
        "fvreen",
        "fvyire",
        "fxvccl",
        "fynlre",
        "fzbxrl",
        "fabbcl",
        "fbppre",
        "fbcuvr",
        "fcnaxl",
        "fcnexl",
        "fcvqre",
        "fdhveg",
        "fevavinf",
        "fgnegerx",
        "fgnejnef",
        "fgrryref",
        "fgrira",
        "fgvpxl",
        "fghcvq",
        "fhpprff",
        "fhpxvg",
        "fhzzre",
        "fhafuvar",
        "fhcrezna",
        "fhesre",
        "fjvzzvat",
        "flqarl",
        "grdhvreb",
        "gnlybe",
        "graavf",
        "grerfn",
        "grfgre",
        "grfgvat",
        "gurzna",
        "gubznf",
        "guhaqre",
        "guk1138",
        "gvssnal",
        "gvtref",
        "gvttre",
        "gbzpng",
        "gbctha",
        "gblbgn",
        "genivf",
        "gebhoyr",
        "gehfgab1",
        "ghpxre",
        "ghegyr",
        "gjvggre",
        "havgrq",
        "intvan",
        "ivpgbe",
        "ivpgbevn",
        "ivxvat",
        "ibbqbb",
        "iblntre",
        "jnygre",
        "jneevbe",
        "jrypbzr",
        "jungrire",
        "jvyyvnz",
        "jvyyvr",
        "jvyfba",
        "jvaare",
        "jvafgba",
        "jvagre",
        "jvmneq",
        "knivre",
        "kkkkkk",
        "kkkkkkkk",
        "lnznun",
        "lnaxrr",
        "lnaxrrf",
        "lryybj",
        "mkpioa",
        "mkpioaz",
        "mmmmmm"
    ],
    "isDeviceCompletion": false,
    "smsDeviceVerified": false,
    "phoneSignupEnabled": true,
    "validationFields": {
        "email": false,
        "name": false,
        "username": false,
        "password": false
    },
    "initialState": {
        "title": "Sign up for Twitter",
        "section": null,
        "module": "app/pages/signup/signup",
        "cache_ttl": 300,
        "body_class_names": "three-col logged-out ms-windows phx-signup fast-signup",
        "doc_class_names": "route-signup",
        "route_name": "signup",
        "page_container_class_names": "AppContent wrapper wrapper-signup",
        "ttft_navigation": false
    }
}
fat-tire commented 8 years ago

Try running the list through here. Make more sense now?

adamdecaf commented 8 years ago

@fat-tire Yea, I was just running it though from the js on the site.

000000
111111
11111111
112233
121212
123123
123456
1234567
12345678
123456789
131313
232323
654321
666666
696969
777777
7777777
8675309
987654
aaaaaa
abc123
abc123
abcdef
abgrtyu
access
access14
action
albert
alberto
alexis
alejandra
alejandro
amanda
amateur
america
andrea
andrew
angela
angels
animal
anthony
apollo
apples
arsenal
arthur
asdfgh
asdfgh
ashley
asshole
august
austin
badboy
bailey
banana
barney
baseball
batman
beatriz
beaver
beavis
bigcock
bigdaddy
bigdick
bigdog
bigtits
birdie
bitches
biteme
blazer
blonde
blondes
blowjob
blowme
bond007
bonita
bonnie
booboo
booger
boomer
boston
brandon
brandy
braves
brazil
bronco
broncos
bulldog
buster
butter
butthead
calvin
camaro
cameron
canada
captain
carlos
carter
casper
charles
charlie
cheese
chelsea
chester
chicago
chicken
cocacola
coffee
college
compaq
computer
consumer
cookie
cooper
corvette
cowboy
cowboys
crystal
cumming
cumshot
dakota
dallas
daniel
danielle
debbie
dennis
diablo
diamond
doctor
doggie
dolphin
dolphins
donald
dragon
dreams
driver
eagle1
eagles
edward
einstein
erotic
estrella
extreme
falcon
fender
ferrari
firebird
fishing
florida
flower
flyers
football
forever
freddy
freedom
fucked
fucker
fucking
fuckme
fuckyou
gandalf
gateway
gators
gemini
george
giants
ginger
gizmodo
golden
golfer
gordon
gregory
guitar
gunner
hammer
hannah
hardcore
harley
heather
helpme
hentai
hockey
hooters
horney
hotdog
hunter
hunting
iceman
iloveyou
internet
iwantu
jackie
jackson
jaguar
jasmine
jasper
jennifer
jeremy
jessica
johnny
johnson
jordan
joseph
joshua
junior
justin
killer
knight
ladies
lakers
lauren
leather
legend
letmein
letmein
little
london
lovers
maddog
madison
maggie
magnum
marine
mariposa
marlboro
martin
marvin
master
matrix
matthew
maverick
maxwell
melissa
member
mercedes
merlin
michael
michelle
mickey
midnight
miller
mistress
monica
monkey
monkey
monster
morgan
mother
mountain
muffin
murphy
mustang
naked
nascar
nathan
naughty
ncc1701
newyork
nicholas
nicole
nipple
nipples
oliver
orange
packers
panther
panties
parker
password
password
password1
password12
password123
patrick
peaches
peanut
pepper
phantom
phoenix
player
please
pookie
porsche
prince
princess
private
purple
pussies
qazwsx
qwerty
qwertyui
rabbit
rachel
racing
raiders
rainbow
ranger
rangers
rebecca
redskins
redsox
redwings
richard
robert
roberto
rocket
rosebud
runner
rush2112
russia
samantha
sammy
samson
sandra
saturn
scooby
scooter
scorpio
scorpion
sebastian
secret
sexsex
shadow
shannon
shaved
sierra
silver
skippy
slayer
smokey
snoopy
soccer
sophie
spanky
sparky
spider
squirt
srinivas
startrek
starwars
steelers
steven
sticky
stupid
success
suckit
summer
sunshine
superman
surfer
swimming
sydney
tequiero
taylor
tennis
teresa
tester
testing
theman
thomas
thunder
thx1138
tiffany
tigers
tigger
tomcat
topgun
toyota
travis
trouble
trustno1
tucker
turtle
twitter
united
vagina
victor
victoria
viking
voodoo
voyager
walter
warrior
welcome
whatever
william
willie
wilson
winner
winston
winter
wizard
xavier
xxxxxx
xxxxxxxx
yamaha
yankee
yankees
yellow
zxcvbn
zxcvbnm
zzzzzz