Default passwords for IoT devices and for web applications (for ex. MySQL and PostgreSQL admin panels). 🐱💻
Useful for fans of Shodan, Censys and Google dorks.
- in progress
Motivation
- one document for the vendors default credentials with high-quality entries
- encouragent participation in the open source community by taking part in Hacktoberfest
- archiving credentials of no longer available in the web
Stats
Number of collected default passwords: 2788
.
Places in the world where the project page was displayed:
As you can see, most people are from India, Russia and United States. The goal is for the entire map to turn blue.
Navigation
Credentials are in the passwords.csv file (the data is in the form of a table) or project website.
Each entries contains: Vendor
, Model/Software name
, Version
, Access Type
, Username
, Password
, Privileges
and Notes
.
Pass Station
Pass Station is CLI & library to search for default credentials, created by @noraj.
As of 1.2.3 version Many passwords have been added as one of the sources of credentials.
Doc: https://noraj.github.io/pass-station/#/
Contribution
Contribute by checking the CONTRIBUTING.md file in main repo.
Sources
Entries are gathered from different sources:
- Vendors documentations/blogs
- ics-default-passwords
- SecLists - Passwords/Default-Credentials
- BetterDefaultPasslist
- RouterSploit
- changeme
- DefaultCreds-cheat-sheet
- Cirt
- Saynamweb
- URTech.ca
- Datarecorvery.com
- RouterReset
Special thanks
Thank you so much all contributors for their contribution to this project. I hope you will contribute to the open source community again!
Special thanks to:
- @MarcelCoding - created Github Action which streamlined and accelerated the work;
- @Mpcs - made very big changes to the project website - change of appearance, grid layout, search bar, navigation bar, About Us page, floating button go to the top, link to repo (contributing button), cleaner code;
- @alenquer - created the first version of the project page;
- @secondl1ght - semantic, accessibility, styling and DRY improvements and format code in all files to be cleaner;
- @zeno4ever - adding a lot of ip cameras, over 50 entries;
- @noraj - adding many entries and helping sanitize the database;
- @Glowstik-YT - created new logo;
- @SurendarSingh and @rahulbhatt1899 - added contact form pull/14 and pull/8;
- @NgoQuocBao1010 - added buttons for downloads passwords to CSV and JSON file and displaying the number of collected passwords on the home page;
- @all contributors - I cannot list all of you, thank you all for your contribution!