What a Wordlist Actually Is
A wordlist is nothing more exotic than a text file with one candidate password per line. When a tool "brute-forces" a login or a password hash with a wordlist, it is not trying every possible combination of characters — it is working through that file, line by line, testing each entry until one matches or the file runs out. The technique is really called a dictionary attack, and its whole effectiveness comes down to one question: is the target's password somewhere in your file?
That framing matters, because it explains both why wordlist attacks work so often and why they are the first thing a defender should design against. People reuse passwords, they pick words with predictable substitutions, and those choices end up in the public breach corpora that every serious wordlist is built from. A strong, unique, high-entropy password is simply not in anyone's list.
Why we practise this at all
Understanding how an attacker chooses and builds a wordlist is what lets you set a password policy that actually resists one, size a lockout threshold sensibly, and read your own auth logs for what a real attempt looks like. Everything below is meant for a lab you own and systems you are authorised to test.
The Wordlists Already on Your Kali Box
A default Kali install ships with a surprising amount of material under /usr/share/wordlists. Before downloading anything, it is worth seeing what you already have:
ls -lh /usr/share/wordlists/
The one everybody reaches for first is rockyou.txt — around fourteen million passwords recovered from a 2009 breach. On Kali it arrives compressed, so the first time you use it you decompress it in place:
sudo gzip -d /usr/share/wordlists/rockyou.txt.gz wc -l /usr/share/wordlists/rockyou.txt
That wc -l is a habit worth keeping: it tells you how many candidates a run will have to get through, which is the difference between a job that finishes over coffee and one that runs for a week.
Two other collections are worth knowing about. SecLists is a large, well-organised repository of wordlists for every context — usernames, web directories, subdomains, default credentials, and passwords sorted by likelihood:
sudo apt update && sudo apt install seclists ls /usr/share/seclists/Passwords/
And Metasploit ships its own set, handy when you are already working inside that framework:
ls -lh /usr/share/metasploit-framework/data/wordlists/
Choosing the Right List Instead of the Biggest One
The beginner's instinct is to point the fourteen-million-line file at everything. It is almost always the wrong move. A targeted attack — a few thousand well-chosen candidates — succeeds more often and finishes far sooner than an exhaustive one, because it is built around what you actually know about the target.
- Start small, escalate later. SecLists ships lists like
10-million-password-list-top-1000.txtfor exactly this. If the top thousand or top ten thousand does not land, then reach for rockyou. - Match the list to the context. A web login, an SSH service, and a Wi-Fi handshake each have their own likely-password profiles. Use a themed list, not a generic dump.
- Mind the minimum length. A WPA2 passphrase must be at least eight characters, so filtering shorter entries out of a general list before a Wi-Fi run saves time on candidates that can never match.
Building Your Own Wordlist with crunch
Sometimes no existing list fits — you know the target's password format but not the value. crunch generates candidates from a pattern. Be careful: the output grows explosively, so always estimate the size before you commit to it.
The basic form takes a minimum length, a maximum length, and a character set:
crunch 8 8 abcdefghijklmnopqrstuvwxyz0123456789 -o custom.txt
That single line describes every eight-character string of lowercase letters and digits — trillions of them, hundreds of terabytes on disk. You would never run it as written; it is here to show why patterns matter. crunch's placeholder syntax lets you pin down what you know and only vary what you don't. Using @ for a lowercase letter, , for uppercase, % for a digit and ^ for a symbol:
crunch 9 9 -t Secure@%% -o custom.txt
That produces only the strings beginning "Secure", followed by one lowercase letter and two digits — a few thousand candidates instead of trillions. When you know a company enforces "Word + two digits", this is how you model it.
How the Hash Side Fits In
Online attacks — throwing candidates at a live login — are slow and noisy, and any competent system will lock you out. The more common lab exercise is offline: you have recovered a password hash and you want to know how quickly a wordlist would break it, because that tells you how well that password was chosen.
First, identify what kind of hash you are holding. hashid reads the format and tells you the likely algorithm:
echo -n "hunter2" | sha1sum hashid ''
Knowing the algorithm matters because it decides the "mode" you hand to the cracker and, more importantly, how expensive each guess is. A fast general-purpose hash like unsalted MD5 or SHA-1 is a poor way to store passwords precisely because a GPU can test billions of guesses a second against it. A purpose-built password hash such as bcrypt is deliberately slow, so the same wordlist that cracks an MD5 in seconds may be hopeless against bcrypt — which is exactly why bcrypt, scrypt or Argon2 is what you should be storing.
John the Ripper
John is the friendliest place to start because it auto-detects many formats. Point it at a file of hashes with a wordlist:
john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt john --show hashes.txt
The second command reprints anything already cracked, since John stores results in a "pot" file and will not repeat work.
hashcat and rules
hashcat is the GPU-accelerated option, and its real power for wordlist work is rules: transformations applied to every entry on the fly, so a hundred-thousand-line list can test millions of realistic variations without ever growing on disk. This is how a cracker models the way people actually mangle words — capitalising the first letter, appending a year, swapping "a" for "@".
hashcat -m 0 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule
Here -m 0 selects raw MD5, -a 0 is straight wordlist mode, and best64.rule is a well-known ruleset that captures the most common mutations. Change the mode number to match the algorithm hashid reported.
Reading the Result as a Defender
The point of the exercise is what the outcome tells you. If a password falls to the top-1000 list, it was catastrophically weak. If it falls to rockyou with best64 rules, it was a dictionary word with predictable mangling — still weak. If a well-resourced run against a slow hash gets nowhere, the password had genuine entropy and the storage was done properly. Each of those is a finding you can act on.
Turning that into policy is straightforward:
- Store passwords with a slow, salted algorithm — bcrypt, scrypt or Argon2 — never raw MD5 or SHA-family hashes. This is the single change that most blunts an offline wordlist attack.
- Push for length over complexity. A long passphrase defeats a dictionary attack far more reliably than a short password with a mandatory symbol, because length is what takes a candidate out of every existing list.
- Rate-limit and lock out online attempts so a live dictionary run is throttled to uselessness long before it works through even a small list.
- Screen new passwords against a breach corpus — the very lists an attacker would use — and reject any that appear in one.
Wrapping Up
Wordlist attacks are simple in concept and unforgiving in practice: they succeed exactly when a password was predictable and fail exactly when it was not. Working through them in a lab — choosing a targeted list, generating a custom one with crunch, identifying a hash and running it through John or hashcat — is the fastest way to understand why the defensive advice you have heard a hundred times actually holds. Practise it only against systems you own or have written permission to test, and let every result feed back into how you and the people you protect choose and store passwords.



