Crafting tailored wordlists with Wordsmith

BSidesLV 2016

Presented by: Sanjiv Kawa, Tom Porter
Date: Wednesday August 03, 2016
Time: 10:00 - 10:50
Location: Tuscany
Track: Passwords

Standard wordlists such as Uniq and Rockyou are great when used with a variety of hashcat rules and big hash sets. But what about the hashes that you aren't able to crack? And what about smaller hash sets from smaller targets?

Queue Wordsmith, a tool that creates wordlists that are tailored to the target. Based on the target's U.S. State, Wordsmith creates geo-location based wordlists that contains the names of cities, landmarks, roads, sports teams, zip codes, area codes, popular names and more. Generated wordlists can be used by themselves or as a supplement to other wordlists for brute force attacks or hash cracking.

Sanjiv Kawa

Most of my interests are with penetration testing networks and applications. I've recently started to get into development, automation and reverse engineering. When my laptop battery dies I tend to go mountain biking, snowboarding, play guitar or watch Arsenal.

Tom Porter

Tom (@porterhau5) is a penetration tester by trade, however his roots are on the blue team writing netflow analytics and providing network situational awareness. Tom holds a handful of certifications from SANS (GPEN, GCIH, GCIA), as well as degrees in Mathematics and CS. When there's not a baseball game nearby, he can be found scripting, participating in CTFs, dissecting packets, tinkering in his homelab, performing password analysis, or chasing high IBUs.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats