
مخطط بيانات الاعتماد
Credmap هي أداة مفتوحة المصدر تم إنشاؤها للتوعية بمخاطر إعادة استخدام بيانات الاعتماد. وهي قادرة على اختبار بيانات اعتماد المستخدم المقدمة على عدة مواقع معروفة لاختبار ما إذا كانت كلمة المرور قد أعيد استخدامها على أي منها. يمكن العثور على مقالة تعريفية رسمية هنا.
Usage: credmap.py --email EMAIL | --user USER | --load LIST [options]
Options:
-h/--help show this help message and exit
-v/--verbose display extra output information
-u/--username=USER.. set the username to test with
-p/--password=PASS.. set the password to test with
-e/--email=EMAIL set an email to test with
-l/--load=LOAD_FILE load list of credentials in format USER:PASSWORD
-f/--format=CRED_F.. format to use when reading from file (e.g. u|e:p)
-x/--exclude=EXCLUDE exclude sites from testing
-o/--only=ONLY test only listed sites
-s/--safe-urls only test sites that use HTTPS.
-i/--ignore-proxy ignore system default HTTP proxy
--proxy=PROXY set proxy (e.g. "socks5://192.168.1.2:9050")
--list list available sites to test with
./credmap.py --username janedoe --email [email protected]
./credmap.py -u johndoe -e [email protected] --exclude "github.com, live.com"
./credmap.py -u johndoe -p abc123 -vvv --only "linkedin.com, facebook.com"
./credmap.py -e [email protected] --verbose --proxy "https://127.0.0.1:8080"
./credmap.py --load creds.txt --format "e.u.p"
./credmap.py -l creds.txt -f "u|e:p"
./credmap.py -l creds.txt
./credmap.py --list
يمكن إضافة مواقع جديدة لاختبارها باستخدام credmap عن طريق إنشاء ملف XML جديد في مجلد websites/. لعرض قائمة بجميع العلامات الممكنة التي يمكن استخدامها في ملف XML، يرجى الرجوع إلى الويكي.
البناء والنشر باستخدام ما يلي:
git clone https://github.com/lightos/credmap.git
cd credmap
docker build -t credmap .
docker run -it credmap