# Stardustsky/SaiDict

弱口令,敏感目录,敏感文件等渗透测试常用攻击字典

Repository: https://github.com/Stardustsky/SaiDict
Canonical: https://ross.abutalabs.com/products/saidict
License Family: other
Last push: 2021-12-16T13:41:07+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2854, "days_push": 1721, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1219, forks 270 (observed 2026-08-28T04:04:01.806580+00:00)

## What it is
A curated collection of attack dictionaries for penetration testing, including weak passwords, common usernames, sensitive directory and file name lists, and injection fuzzing payloads. It is organized into categories such as account credentials, middleware and service default passwords, and webshell passwords.

## Use cases
- brute forcing weak passwords on ssh, mysql, ftp, and remote desktop services
- directory and file brute forcing to find sensitive files like backups, archives, and source code
- fuzzing web applications for sql injection, xss, xxe, and ldap injection payloads
- testing default credentials on middleware like tomcat, weblogic, and zabbix
- guessing webshell passwords during authorized penetration tests

## When to choose
- you need a comprehensive Chinese-language-oriented wordlist collection for penetration testing
- you want ready-made dictionaries for common services, middleware, and sensitive file discovery
- you are doing authorized security assessments and need credential and fuzzing wordlists

## When to avoid
- you need actively maintained wordlists with recent updates
- you require a tool that automates attacks rather than raw wordlist data
- your target environment is unrelated to the Chinese web ecosystem covered by many entries

## Facets
- artifact type: dataset
- maturity: maintenance
- function: penetration-testing, security, fuzzing
- domain: security, penetration-testing, developer-tools
- platform: cross-platform
- tags: wordlist, dictionary, brute-force, fuzzing-dictionaries, weak-passwords, sensitive-files, dirbusting

## Member repositories
- Stardustsky/SaiDict (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:01.806580+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:16:11.922521+00:00, confidence not recorded.
  - readme: https://github.com/Stardustsky/SaiDict (fetched 2026-08-28T04:04:01.806580+00:00, sha c261ab750105)
- Data as of 2026-08-30T08:39:29.467469+00:00.
