wordlists.nix (1690B)
1 # modules/features/pentest/wordlists.nix — $WORDLISTS, the tree every fuzzer 2 # and cracker is pointed at. 3 # 4 # $WORDLISTS/rockyou.txt 14 M passwords, plain text 5 # $WORDLISTS/seclists/ the SecLists checkout (1.9 G) 6 # $WORDLISTS/nmap.lst wfuzz/ the smaller sets 7 # 8 # nixpkgs' `wordlists` already aggregates seclists, rockyou, nmap.lst and wfuzz 9 # under one share/wordlists, and already ships rockyou DECOMPRESSED — so this 10 # module points at that tree instead of rebuilding it. The check still asserts 11 # rockyou is plain text: it has shipped gzipped before, and a gzip magic number 12 # would make every `hashcat ... rockyou.txt` silently crack nothing. 13 # 14 # `wordlists` also provides `wordlists_path`, so the shell can find the tree 15 # without $WORDLISTS. 16 { lib, ... }: 17 (import ./_sets.nix { inherit lib; }) { 18 name = "wordlists"; 19 description = "seclists, rockyou and the exploit-db archive"; 20 21 packages = pkgs: [ 22 pkgs.wordlists # seclists + rockyou + nmap.lst + wfuzz, and `wordlists_path` 23 pkgs.exploitdb # `searchsploit` 24 ]; 25 26 expectedBins = [ "wordlists_path" "searchsploit" ]; 27 28 checkScript = { pkgs, lib }: '' 29 dir=${pkgs.wordlists}/share/wordlists 30 for p in rockyou.txt seclists nmap.lst; do 31 if [ ! -e "$dir/$p" ]; then 32 echo "pentest-wordlists: $dir/$p is missing" >&2 33 exit 1 34 fi 35 done 36 if [ "$(head -c2 "$dir/rockyou.txt" | od -An -tx1 | tr -d ' ')" = "1f8b" ]; then 37 echo "pentest-wordlists: rockyou.txt is gzipped, not plain text" >&2 38 exit 1 39 fi 40 ''; 41 42 extraConfig = { pkgs, lib, ... }: { 43 environment.sessionVariables.WORDLISTS = lib.mkForce "${pkgs.wordlists}/share/wordlists"; 44 }; 45 }