danielmiessler / SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

Home Page:https://www.owasp.org/index.php/OWASP_Internet_of_Things_Project

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

A warning message should be added to main page

Wernfried opened this issue · comments

Some time ago I cloned this repository to my working PC. I was interested only in text file of default passwords.
However, our IT security considered this repository as malware (I had some trouble and non-nice discussions with them), because it also contains a lot of "bad" software peaces or at least suspicious patterns. Nothing was executed and there was no threat, however if the "gods" from IT security department say you do something bad, then you can run into big trouble.

You may put a warning message to the main page, that this repository can cause alerts in your virus scanner/defender software when you download or clone it.

@Wernfried If it was a single file, then maybe using the web UI would of been easier ;)

The "About SecList" does say:

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more. The goal is to enable a security tester to pull this repository onto a new testing box and have access to every type of list that may be needed.

From a security point of view "Payloads" and "web shells" would hint to me that there could be false positives with malware/antivirus solutions.

With that said, please do open up a PR if you wish for it to be added