
ईमेल OSINT और पासवर्ड उल्लंघन शिकार उपकरण, स्थानीय रूप से या प्रीमियम सेवाओं का उपयोग करना। संबंधित ईमेल का पता लगाने में सहायता करता है
h8mail एक ईमेल OSINT और उल्लंघन शिकार उपकरण है जो विभिन्न उल्लंघन और टोही सेवाओं, या स्थानीय उल्लंघनों जैसे Troy Hunt का "Collection1" और कुख्यात "Breach Compilation" टॉरेंट का उपयोग करता है।
pip के माध्यम से उपलब्ध, केवल requests की आवश्यकता हैpip3 install h8mail🔑 - API कुंजी आवश्यक
usage: h8mail [-h] [-t USER_TARGETS [USER_TARGETS ...]]
[-u USER_URLS [USER_URLS ...]] [-q USER_QUERY] [--loose]
[-c CONFIG_FILE [CONFIG_FILE ...]] [-o OUTPUT_FILE]
[-j OUTPUT_JSON] [-bc BC_PATH] [-sk]
[-k CLI_APIKEYS [CLI_APIKEYS ...]]
[-lb LOCAL_BREACH_SRC [LOCAL_BREACH_SRC ...]]
[-gz LOCAL_GZIP_SRC [LOCAL_GZIP_SRC ...]] [-sf]
[-ch [CHASE_LIMIT]] [--power-chase] [--hide] [--debug]
[--gen-config]
Email information and password lookup tool
optional arguments:
-h, --help show this help message and exit
-t USER_TARGETS [USER_TARGETS ...], --targets USER_TARGETS [USER_TARGETS ...]
Either string inputs or files. Supports email pattern
matching from input or file, filepath globing and
multiple arguments
-u USER_URLS [USER_URLS ...], --url USER_URLS [USER_URLS ...]
Either string inputs or files. Supports URL pattern
matching from input or file, filepath globing and
multiple arguments. Parse URLs page for emails.
Requires http:// or https:// in URL.
-q USER_QUERY, --custom-query USER_QUERY
Perform a custom query. Supports username, password,
ip, hash, domain. Performs an implicit "loose" search
when searching locally
--loose Allow loose search by disabling email pattern
recognition. Use spaces as pattern seperators
-c CONFIG_FILE [CONFIG_FILE ...], --config CONFIG_FILE [CONFIG_FILE ...]
Configuration file for API keys. Accepts keys from
Snusbase, WeLeakInfo, Leak-Lookup, HaveIBeenPwned,
Emailrep, Dehashed and hunterio
-o OUTPUT_FILE, --output OUTPUT_FILE
File to write CSV output
-j OUTPUT_JSON, --json OUTPUT_JSON
File to write JSON output
-bc BC_PATH, --breachcomp BC_PATH
Path to the breachcompilation torrent folder. Uses the
query.sh script included in the torrent
-sk, --skip-defaults Skips Scylla and HunterIO check. Ideal for local scans
-k CLI_APIKEYS [CLI_APIKEYS ...], --apikey CLI_APIKEYS [CLI_APIKEYS ...]
Pass config options. Supported format: "K=V,K=V"
-lb LOCAL_BREACH_SRC [LOCAL_BREACH_SRC ...], --local-breach LOCAL_BREACH_SRC [LOCAL_BREACH_SRC ...]
Local cleartext breaches to scan for targets. Uses
multiprocesses, one separate process per file, on
separate worker pool by arguments. Supports file or
folder as input, and filepath globing
-gz LOCAL_GZIP_SRC [LOCAL_GZIP_SRC ...], --gzip LOCAL_GZIP_SRC [LOCAL_GZIP_SRC ...]
Local tar.gz (gzip) compressed breaches to scans for
targets. Uses multiprocesses, one separate process per
file. Supports file or folder as input, and filepath
globing. Looks for 'gz' in filename
-sf, --single-file If breach contains big cleartext or tar.gz files, set
this flag to view the progress bar. Disables
concurrent file searching for stability
-ch [CHASE_LIMIT], --chase [CHASE_LIMIT]
Add related emails from hunter.io to ongoing target
list. Define number of emails per target to chase.
Requires hunter.io private API key if used without
power-chase
--power-chase Add related emails from ALL API services to ongoing
target list. Use with --chase
--hide Only shows the first 4 characters of found passwords
to output. Ideal for demonstrations
--debug Print request debug information
--gen-config, -g Generates a configuration file template in the current
working directory & exits. Will overwrite existing
h8mail_config.ini file
$ h8mail -t [email protected]
pwned_targets.csv में दें$ h8mail -t targets.txt -c config.ini -o pwned_targets.csv
$ h8mail -t targets.txt -bc ../Downloads/BreachCompilation/ -k "snusbase_token=$snusbase_token"
$ h8mail -t targets.txt -bc ../Downloads/BreachCompilation/ -sk
$ h8mail -t targets.txt -gz /tmp/Collection1/ -sk
$ h8mail -t [email protected] -lb /tmp/4k_Combo.txt -ch 10 -k "hunterio=ABCDE123"
$ h8mail -t JSmith89 -q username -k "[email protected]" "dehashed_key=ABCDE123"
$ h8mail -t 42.202.0.42 -q ip -c h8mail_config_priv.ini -ch 2 --power-chase
$ h8mail -u "https://pastebin.com/raw/kQ6WNKqY" "list_of_urls.txt"
💜 h8mail निम्न में पाया जा सकता है:
k at khast3x dot club पर ईमेल भेज सकते हैं (PGP अनुकूल)# curl + gpg pro tip: import ktx's keys
curl https://keybase.io/ktx/pgp_keys.asc | gpg --import
# the Keybase app can push to gpg keychain, too
keybase pgp pull ktx
यदि आप इस परियोजना पर अपडेट रहना चाहते हैं:
| सेवा | कार्य | स्थिति |
|---|
| HaveIBeenPwned(v3) | ईमेल उल्लंघनों की संख्या | ✅ 🔑 |
| HaveIBeenPwned Pastes(v3) | लक्ष्यों का उल्लेख करने वाली टेक्स्ट फ़ाइलों के URL | ✅ 🔑 |
| Hunter.io - Public | संबंधित ईमेलों की संख्या | ✅ |
| Hunter.io - Service (free tier) | क्लियरटेक्स्ट संबंधित ईमेल, पीछा करना | ✅ 🔑 |
| Snusbase - Service | क्लियरटेक्स्ट पासवर्ड, हैश और सॉल्ट, उपयोगकर्ता नाम, आईपी - तेज़ ⚡ | ✅ 🔑 |
| Leak-Lookup - Public | खोजने योग्य उल्लंघन परिणामों की संख्या | ✅ (🔑) |
| Leak-Lookup - Service | क्लियरटेक्स्ट पासवर्ड, हैश और सॉल्ट, उपयोगकर्ता नाम, आईपी, डोमेन | ✅ 🔑 |
| Emailrep.io - Service (free) | उल्लंघनों में अंतिम बार देखा गया, सोशल मीडिया प्रोफाइल | ✅ 🔑 |
| scylla.so - Service (free) | क्लियरटेक्स्ट पासवर्ड, हैश और सॉल्ट, उपयोगकर्ता नाम, आईपी, डोमेन | 🚧 |
| Dehashed.com - Service | क्लियरटेक्स्ट पासवर्ड, हैश और सॉल्ट, उपयोगकर्ता नाम, आईपी, डोमेन | ✅ 🔑 |
| IntelX.io - Service (free trial) | क्लियरटेक्स्ट पासवर्ड, हैश और सॉल्ट, उपयोगकर्ता नाम, आईपी, डोमेन, बिटकॉइन वॉलेट, IBAN | ✅ 🔑 |
| 🆕 Breachdirectory.org - Service (free) | क्लियरटेक्स्ट पासवर्ड, हैश और सॉल्ट, उपयोगकर्ता नाम, डोमेन | 🚧 🔑 |