← All cheat sheets

TWOFI

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

twofi (Twitter Words of Interest) creates personalized wordlists
from a target's Twitter activity. It scrapes tweets to build custom
wordlists useful for password attacks based on the target's
interests, vocabulary, and frequently used terms.

BASIC USAGE#

twofi --users <username>         # Generate wordlist from user
twofi --searches <term>          # Generate from search term

OPTIONS#

twofi -u <username>              # Target Twitter username
twofi --users <user1,user2>     # Multiple usernames
twofi -s <term>                  # Search term
twofi --searches <t1,t2>        # Multiple search terms
twofi -m <min_length>            # Minimum word length
twofi -T <count>                 # Number of tweets to fetch
twofi -c <file>                  # Config file path
twofi -v                         # Verbose output

OUTPUT OPTIONS#

twofi -u <username> > wordlist.txt
                                 # Save to file
twofi -u <username> | sort -u    # Remove duplicates
twofi -u <username> | sort -u | wc -l
                                 # Count unique words

EXAMPLES#

# Generate wordlist from single user
twofi -u targetuser > wordlist.txt

# Multiple users with minimum word length
twofi --users user1,user2,user3 -m 6 > wordlist.txt

# Search-based wordlist
twofi --searches "company name" > wordlist.txt

# Combined users and searches
twofi -u targetuser -s "company" > wordlist.txt

# Verbose output with 500 tweets
twofi -u targetuser -T 500 -v > wordlist.txt

# Filter short words
twofi -u targetuser -m 8 > long_words.txt

CONFIGURATION#

# Config file: ~/.twofi
# Required: Twitter API keys

# Config format:
api_key=YOUR_API_KEY
api_secret=YOUR_API_SECRET

WORDLIST ENHANCEMENT#

# Combine with other tools:

# Add common mutations
john --wordlist=twofi_list.txt --rules --stdout > mutated.txt

# Combine with CeWL output
cat twofi_list.txt cewl_list.txt | sort -u > combined.txt

# Use with hashcat rules
hashcat -m <type> hash.txt twofi_list.txt -r rules/best64.rule

# Use with Hydra
hydra -l <user> -P twofi_list.txt <target> ssh

NOTES#

- Requires Twitter API access (API keys)
- Twitter API rate limits apply
- Ruby-based tool
- Best results with active Twitter users
- Combine with CeWL for web-scraped words
- Useful for targeted password attacks
- Personal information often used in passwords
- Social engineering intelligence gathering