
OSINT-Tool zum Auffinden von kompromittierten E-Mails, Datenbanken, Pastes und relevanten Informationen
WhatBreach ist ein OSINT-Tool, das die Aufgabe vereinfacht, herauszufinden, in welchen Datenlecks eine E-Mail-Adresse aufgetaucht ist. WhatBreach bietet eine einfache und effektive Möglichkeit, entweder mehrere oder eine einzelne E-Mail-Adresse zu durchsuchen und alle bekannten Datenlecks zu entdecken, in denen diese E-Mail gesehen wurde. Von dort aus ist WhatBreach in der Lage, die Datenbank herunterzuladen, falls sie öffentlich verfügbar ist, die Pastes herunterzuladen, in denen die E-Mail gesehen wurde, oder die Domain der E-Mail für weitere Untersuchungen zu durchsuchen. Um diese Aufgabe erfolgreich durchzuführen, nutzt WhatBreach die folgenden Websites und/oder APIs:
Einige interessante Funktionen von WhatBreach sind die folgenden:
Hilfeseite:
usage: whatbreach.py [-h] [-e EMAIL] [-l PATH] [-nD] [-nP] [-sH] [-wL] [-dP]
[-vH] [-cT] [-d] [-s DIRECTORY-PATH] [--throttle TIME]
optional arguments:
-h, --help show this help message and exit
mandatory opts:
-e EMAIL, --email EMAIL
Pass a single email to scan for
-l PATH, -f PATH, --list PATH, --file PATH
Pass a file containing emails one per line to scan
search opts:
-nD, --no-dehashed Suppres dehashed output
-nP, --no-pastebin Suppress Pastebin output
-sH, --search-hunter Search hunter.io with a provided email address and
query for all information, this will process all
emails found as normal
-wL, --search-weleakinfo
Search weleakinfo.com as well as HIBP for results
misc opts:
-dP, --download-pastes
Download pastes associated with the email address
found (if any)
-vH, --verify-hunter Verify the emails found on hunter.io for deliverable
status
-cT, --check-ten-minute
Check if the provided email address is a ten minute
email or not
-d, --download Attempt to download the database if there is one
available
-s DIRECTORY-PATH, --save-dir DIRECTORY-PATH
Pass a directory to save the downloaded databases into
instead of the `HOME` path
--throttle TIME Throttle the HIBP requests to help prevent yourself
from being blocked
Einfache E-Mail-Suche:
python whatbreach.py -e [email protected]
_____
_ _ _ _ _ _____ _ |___ |
| | | | |_ ___| |_| __ |___ ___ ___ ___| |_ | _|
| | | | | .'| _| __ -| _| -_| .'| _| | |_|
|_____|_|_|__,|_| |_____|_| |___|__,|___|_|_|[][][]|_|
Find emails and their associated leaked databases.. v0.1.5
[ i ] starting search on single email address: [email protected]
[ i ] searching breached accounts on HIBP related to: [email protected]
[ i ] searching for paste dumps on HIBP related to: [email protected]
[ i ] found a total of 9 database breach(es) pertaining to: [email protected]
---------------------------------------------------------------------------
Breach/Paste: | Database/Paste Link:
Dailymotion | https://www.dehashed.com/search?query=Dailymotion
500px | https://www.dehashed.com/search?query=500px
LinkedIn | https://www.dehashed.com/search?query=LinkedIn
MyFitnessPal | https://www.dehashed.com/search?query=MyFitnessPal
Bolt | https://www.dehashed.com/search?query=Bolt
Dropbox | https://www.dehashed.com/search?query=Dropbox
Lastfm | https://www.dehashed.com/search?query=Lastfm
Apollo | https://www.dehashed.com/search?query=Apollo
OnlinerSpambot | N/A
---------------------------------------------------------------------------
Suche mit weleakinfo und haveibeenpwned:
python whatbreach.py -e [email protected] -wL
_____
_ _ _ _ _ _____ _ |___ |
| | | | |_ ___| |_| __ |___ ___ ___ ___| |_ | _|
| | | | | .'| _| __ -| _| -_| .'| _| | |_|
|_____|_|_|__,|_| |_____|_| |___|__,|___|_|_|[][][]|_|
Find emails and their associated leaked databases.. v0.1.5