
Herramienta CLI para consultar la API de Have I Been Pwned en busca de cuentas violadas, pastes y exposición de contraseñas, lo que permite una evaluación rápida de la seguridad de credenciales comprometidas.
Una herramienta de línea de comandos para consultar el servicio [Have I been pwned?][haveibeenpwned] de [Troy Hunt][troy] utilizando el módulo [hibp][hibp] de Node.js.
[![npm Version][npm-image]][npm-url] [![Build Status][ci-image]][ci-url]
Descargue e instale [Node.js][nodejs], luego instale pwned globalmente usando npm:
npm install pwned -g
Alternativamente, puede ejecutarlo bajo demanda usando el ejecutor de paquetes [npx][npx]:
npx pwned
El 18 de julio de 2019, la API de haveibeenpwned.com movió varios servicios detrás de la autenticación, requiriendo una clave API. Consulte [la publicación del blog de Troy][api-key-blog-post] para conocer la justificación y una explicación completa. Para usar algunos de los comandos de pwned (por ejemplo, ba, pa y search), necesitará [obtener una clave API][get-api-key] y ejecutar pwned apiKey para configurar pwned. Los otros comandos no requieren una clave API y puede usarlos sin obtener una.
pwned <command>
Commands:
pwned apiKey [key] set the API key to be used for authenticated requests
pwned ba <account|email> get all breaches for an account (username or email address)
pwned bd <domain> get all breached email addresses for a domain
pwned breach <name> get a single breached site by breach name
pwned breaches get all breaches in the system
pwned dc get all data classes in the system
pwned lb get the most recently added breach
pwned pa <email> get all pastes for an account (email address)
pwned pw <password> securely check a password for public exposure
pwned sd get all subscribed domains for your account
pwned search <account|email> search breaches and pastes for an account (username or email
address)
pwned slbe <email> get all stealer log domains for an email address
pwned slbed <email-domain> get all stealer log email aliases for an email domain
pwned slbwd <website-domain> get all stealer log email addresses for a website domain
pwned subStatus get the subscription status of your API key
Options:
-h, --help Show help [boolean]
-v, --version Show version number [boolean]
Obtener todas las filtraciones para una cuenta:
$ pwned ba [email protected]
✔ Good news — no pwnage found!
Obtener todas las filtraciones en el sistema, filtrando los resultados solo al dominio 'adobe.com':
$ pwned breaches -d adobe.com
-
Title: Adobe
Name: Adobe
Domain: adobe.com
BreachDate: 2013-10-04
AddedDate: 2013-12-04T00:00:00Z
ModifiedDate: 2013-12-04T00:00:00Z
PwnCount: 152445165
Description: In October 2013, 153 million Adobe accounts were breached with each containing an internal ID, username, email, <em>encrypted</em> password and a password hint in plain text. The password cryptography was poorly done and <a href="http://stricture-group.com/files/adobe-top100.txt" target="_blank" rel="noopener">many were quickly resolved back to plain text</a>. The unencrypted hints also <a href="http://www.troyhunt.com/2013/11/adobe-credentials-and- serious.html" target="_blank" rel="noopener">disclosed much about the passwords</a> adding further to the risk that hundreds of millions of Adobe customers already faced.
DataClasses:
- Email addresses
- Password hints
- Passwords
- Usernames
IsVerified: true
IsFabricated: false
IsSensitive: false
IsActive: true
IsRetired: false
IsSpamList: false
LogoType: svg
Obtener un único sitio filtrado por nombre de filtración:
$ pwned breach MyCompany
✔ No breach found by that name.
Obtener todas las clases de datos en el sistema, devolviendo resultados JSON sin procesar para consumo externo/encadenado:
$ pwned dc --raw
["Account balances","Address book contacts","Age groups","Ages","Apps installed on devices","Astrological signs","Auth tokens","Avatars","Bank account numbers","Banking PINs","Beauty ratings","Biometric data","Browser user agent details","Buying preferences","Car ownership statuses","Career levels","Cellular network names","Charitable donations","Chat logs","Credit card CVV","Credit cards","Credit status information","Customer feedback","Customer interactions","Dates of birth","Deceased date","Deceased statuses","Device information","Device usage tracking data","Drinking habits","Drug habits","Eating habits","Education levels","Email addresses","Email messages","Employers","Ethnicities","Family members' names","Family plans","Family structure","Financial investments","Financial transactions","Fitness levels","Genders","Geographic locations","Government issued IDs","Health insurance information","Historical passwords","Home ownership statuses","Homepage URLs","IMEI numbers","IMSI numbers","Income levels","Instant messenger identities","IP addresses","Job titles","MAC addresses","Marital statuses","Names","Nationalities","Net worths","Nicknames","Occupations","Parenting plans","Partial credit card data","Passport numbers","Password hints","Passwords","Payment histories","Payment methods","Personal descriptions","Personal health data","Personal interests","Phone numbers","Physical addresses","Physical attributes","Political donations","Political views","Private messages","Professional skills","Profile photos","Purchases","Purchasing habits","Races","Recovery email addresses","Relationship statuses","Religions","Reward program balances","Salutations","School grades (class levels)","Security questions and answers","Sexual fetishes","Sexual orientations","Smoking habits","SMS messages","Social connections","Social media profiles","Spoken languages","Support tickets","Survey results","Time zones","Travel habits","User statuses","User website URLs","Usernames","Utility bills","Vehicle details","Website activity","Work habits","Years of birth","Years of professional experience"]
Obtener todas las pastas para una dirección de correo electrónico: