GO KALI FREE

CeWL

Password Attacks

Beginnerlow risk

CeWL is a custom word list generator that spiders a target URL and creates a wordlist from the content. Great for targeted password attacks.

Installation

sudo apt install cewl

Basic Syntax

cewl <url>

Quick Facts

Full Name
CeWL (Custom Word List generator)
License
GPL
Author
DIGININJA
Written In
Ruby
Platforms
Linux, macOS, Windows (with Ruby)
Category
Wordlist Generation
Input Method
Website Spidering
Key Feature
Target-specific wordlist creation

Tool Overview

CeWL (Custom Word List generator) is a Ruby-based tool that spiders a target website and generates a custom wordlist from the content it finds. Unlike generic wordlists, CeWL creates dictionaries tailored to the specific target organization.

By crawling the target website to a specified depth, CeWL extracts words from page content, including company names, product terms, employee names, and industry jargon. This produces wordlists far more effective than generic lists for password attacks against that specific organization.

CeWL also supports email extraction, making it useful for username enumeration. Combined with password mutation rules in tools like John the Ripper or Hashcat, CeWL-generated wordlists significantly improve password cracking success rates.

Common Commands

cewl example.comSpider a site with default settings and print a wordlist to stdout
cewl -w wordlist.txt example.comWrite the harvested wordlist to a file instead of the screen
cewl -d 3 example.comIncrease the spidering depth to 3 links deep (default is 2)
cewl -d 0 -w page.txt example.comScrape only the single supplied page (no link following)
cewl -m 6 example.comOnly keep words that are at least 6 characters long
cewl -m 5 -d 2 -w wordlist.txt example.comCommon combo: depth 2, minimum length 5, output to file
cewl -c example.comShow the occurrence count next to each word found
cewl --lowercase example.comConvert every parsed word to lowercase
cewl --with-numbers example.comAlso accept words that contain digits, not just letters
cewl -o example.comAllow the spider to follow links to other (offsite) domains
cewl -k example.comKeep the downloaded pages/files on disk after spidering
cewl -e example.comExtract and include email addresses found on the site
cewl -e --email_file emails.txt example.comHarvest emails and write them to a dedicated file
cewl -n -e example.comSkip the wordlist and only output the discovered email addresses
cewl -a example.comInclude document metadata (author, software) via exiftool parsing

Step-by-Step Guide

  1. 1Identify a website belonging to your target organization
  2. 2Execute the tool against the URL
  3. 3Look over the resulting text file to ensure the terms make sense
  4. 4Import this list into your primary authentication testing tools
  5. 5Enhance the list by applying mutation rules

Warnings

Use Cases

Targeted Password Lists

Create wordlists using company-specific terms, products, and jargon from their website.

Username Enumeration

Extract email addresses from websites to build username lists for brute-force attacks.

Social Engineering

Gather words and phrases for crafting targeted phishing emails and social engineering attacks.

CTF Wordlists

Generate custom dictionaries for CTF challenges based on challenge-related websites.

Red Team Operations

Build target-specific password lists for more effective credential attacks.

Key Features

People Also Ask

What is the difference between CeWL and Crunch?

CeWL generates wordlists by spidering a target website, producing target-specific dictionaries. Crunch generates wordlists from character sets and patterns without needing a website. Use CeWL when you have a web target; use Crunch for pattern-based generation like PINs or specific formats.

Can I use CeWL to create WPA wordlists?

Yes. CeWL can generate custom wordlists from target websites that work well for WPA cracking. Spider the target's public website, then feed the output into aircrack-ng: aircrack-ng -w cewl_output.txt capture.cap. Target-specific words often yield better results than generic WPA wordlists.

How does the CeWL depth parameter work?

The -d flag controls how many links deep the spider follows from the starting URL. Depth 0 scrapes only the initial page, depth 1 follows one level of links, depth 2 follows two levels, and so on. Higher depths capture more content but take longer and may produce very large wordlists.

How do I use CeWL output with Hashcat?

First generate the wordlist with CeWL: cewl http://example.com -w wordlist.txt. Then crack with Hashcat using rules for mutations: hashcat -m 0 hashes.txt wordlist.txt -r rules/best64.rule. The rules append numbers, symbols, and capitalization variations to base words.

Can CeWL work offline for phishing wordlists?

CeWL works on live websites only, but you can save pages offline and process them with the -f flag: cewl -f saved_page.html -w wordlist.txt. This is useful for creating phishing target wordlists from previously downloaded content or archived pages.

Is a larger CeWL wordlist always better than a smaller one?

Not necessarily. Quality matters more than size. A focused wordlist from depth 2-3 with -m 5 filtering often cracks more passwords than an unfiltered list with thousands of irrelevant words. Use -c to check word frequency and prioritize high-occurrence terms.

Related Tools

Crunch

Password Attacks

Pattern-based wordlist generator for creating wordlists from character sets and patterns.

John the Ripper

Password Attacks

Password cracker that uses CeWL-generated wordlists with rules for effective cracking.

Hashcat

Password Attacks

GPU-accelerated cracker for maximum speed with CeWL-generated wordlists.

Crunch

Password Attacks

Pattern-based wordlist generator for supplementing CeWL output.

Medusa

Password Attacks

Online brute-forcer for testing CeWL-generated passwords against live services.

Frequently Asked Questions

What is CeWL?

CeWL (Custom Word List generator) is a Ruby-based tool that spiders target websites and generates custom wordlists from the content it finds. It creates dictionaries containing words specific to the target organization for more effective password attacks.

How do I use CeWL for password cracking?

Run CeWL against the target website: cewl http://target.com -w wordlist.txt. Then feed the output into John or Hashcat with rules: john --rules --wordlist=wordlist.txt hashes.txt. The rules mutate base words into common password variations.

Can CeWL extract email addresses?

Yes. Use the -e flag to extract email addresses: cewl http://target.com -e --email_file emails.txt. This is useful for username enumeration and building login credential lists.

What depth should I use for CeWL spidering?

Depth depends on the target website size. Use -d 2 for small sites, -d 3 for medium sites, and -d 4 for large sites with deep navigation. Too shallow misses words; too deep takes too long.

Can CeWL bypass login pages?

CeWL cannot authenticate to websites. It only crawls publicly accessible pages. If important content is behind authentication, use tools that can handle authenticated sessions or request access to a test environment.

How do I combine CeWL with other wordlists?

Use cat to merge CeWL output with rockyou.txt or other base wordlists: cat cewl_output.txt rockyou.txt | sort -u > combined.txt. The -u flag removes duplicates for a clean, combined wordlist.

What does the -m flag do in CeWL?

The -m flag sets the minimum word length: cewl -m 6 http://target.com. Words shorter than the minimum are excluded, reducing noise from short or irrelevant words in the generated list.

How do I exclude certain words from CeWL output?

Use the --exclude flag with regex patterns to filter unwanted words: cewl --exclude='^(test|admin)' http://target.com. This is useful for removing generic or irrelevant terms.

Can CeWL spider multiple pages?

Yes, CeWL follows links up to the configured depth. Use -d to set depth and -w to specify the output file. For multiple starting URLs, run CeWL separately for each or use a script to combine results.

How do I extract only specific content types from CeWL?

Use --meta for meta tag extraction, --email for email addresses, and --lowercase for converting all words to lowercase. These flags help focus the wordlist on specific content types.

Can CeWL work with JavaScript-rendered pages?

CeWL cannot render JavaScript. For JavaScript-heavy sites, use a headless browser to render the page first, save the HTML, then run CeWL on the saved file using the -f flag for file input.

How do I improve CeWL wordlist quality?

Increase spider depth (-d 3-4), set minimum word length (-m 4), use --lowercase for consistency, and combine with rule-based cracking tools to generate variations from base words.

Can CeWL crawl password-protected pages?

No, CeWL cannot authenticate to pages behind login forms. For authenticated content, use tools that support session cookies (like Burp Suite) to capture authenticated content, then run CeWL on the saved HTML files.

How do I extract meta keywords with CeWL?

Use the --meta flag to extract words from HTML meta tags: cewl --meta http://target.com. This captures keywords that webmasters include for SEO, which are often relevant to the organization's vocabulary.

Can CeWL generate wordlists for mobile apps?

CeWL works on URLs, so if you can capture the HTML content from a mobile app's API endpoints or web views, you can feed the saved HTML to CeWL using the -f flag for file input.

How do I filter CeWL output by word length?

Use -m to set minimum word length and -M for maximum: cewl -m 4 -M 15 http://target.com. This filters out very short words (like 'a', 'to') and very long words that are unlikely to be passwords.

Can CeWL work with local HTML files?

Yes, use the -f flag for file input: cewl -f local_page.html -w wordlist.txt. This is useful for processing pre-downloaded content, API responses, or JavaScript-rendered pages captured with a browser.

How do I count word frequency in CeWL output?

Use the --count flag to include word frequency counts in the output: cewl --count http://target.com. Words appearing more frequently on the target site may be more likely to be used in passwords.

Can CeWL extract phone numbers or numbers?

No, CeWL extracts text words and email addresses only. For phone number extraction, use custom scripts or specialized OSINT tools. CeWL is optimized for wordlist generation, not comprehensive data extraction.

Tags

#password-attacks

Output Explanation

Generates a localized text file containing words scraped directly from the provided web pages.

Ethical Usage Notice

This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.