haxxm0nkey/lolcreds-data — explained in plain English
Analysis updated 2026-05-18
Check whether a product you deploy, like Grafana, ships with a default admin password you need to change.
Look up where a service's credentials typically live, such as a config file or environment variable, during a security audit.
Contribute a new product entry or improve an existing one with better public references.
| haxxm0nkey/lolcreds-data | avlcode/avlcode | azureshores/bitcrusher | |
|---|---|---|---|
| Stars | 45 | 45 | 45 |
| Language | — | — | Python |
| Setup difficulty | easy | easy | easy |
| Complexity | 1/5 | 3/5 | 2/5 |
| Audience | ops devops | ops devops | general |
Figures from each repo's GitHub metadata at analysis time.
This repository holds the data behind LOLCreds, a public catalog of known default credentials, credential locations, and exposure patterns for real software products, cloud services, appliances, and deployment tools. The idea is to give security teams and administrators one place to check whether a product they use ships with a default username and password, a generated token, or some other credential that people commonly forget to change. Each product gets its own YAML file under an entries folder. A single entry can describe several kinds of credentials, such as a static default password, a token generated automatically at install time, or a locally created admin account, along with where that credential typically lives, like a config file, an environment variable, a web login page, or a secret manager. Entries also note what the credential can access if left unchanged, and they link out to the vendor documentation, advisories, or release notes the information came from. The example included in the README covers Grafana, showing entries for its default admin login, a distribution-specific password used by a popular Kubernetes Helm chart, locally created user passwords, and service account tokens, each with details on where to find or change them. Contributions are welcome for adding missing products, fixing categories, or improving references, but the project is explicit that only publicly documented information belongs here: no private credentials, leaked secrets, live API keys, or breach data should ever be submitted. The data itself is released under the CC BY 4.0 license, which allows reuse as long as the original source is credited.
A public, community-maintained catalog of known default credentials and where to find them, built from vendor docs and advisories to help teams check and fix their own systems.
Free to reuse and share as long as you credit the original source.
Setup difficulty is rated easy, with roughly 5min to a first successful run.
Mainly ops devops.
This repo across BitVibe Labs
double-check against the repo, no cap.