
Il Mapper delle Credenziali
Credmap è uno strumento open source creato per sensibilizzare sui pericoli del riutilizzo delle credenziali. È in grado di testare le credenziali utente fornite su diversi siti web noti per verificare se la password è stata riutilizzata su qualcuno di essi. Un post introduttivo ufficiale può essere trovato qui.
Usage: credmap.py --email EMAIL | --user USER | --load LIST [options]
Options:
-h/--help show this help message and exit
-v/--verbose display extra output information
-u/--username=USER.. set the username to test with
-p/--password=PASS.. set the password to test with
-e/--email=EMAIL set an email to test with
-l/--load=LOAD_FILE load list of credentials in format USER:PASSWORD
-f/--format=CRED_F.. format to use when reading from file (e.g. u|e:p)
-x/--exclude=EXCLUDE exclude sites from testing
-o/--only=ONLY test only listed sites
-s/--safe-urls only test sites that use HTTPS.
-i/--ignore-proxy ignore system default HTTP proxy
--proxy=PROXY set proxy (e.g. "socks5://192.168.1.2:9050")
--list list available sites to test with
./credmap.py --username janedoe --email [email protected]
./credmap.py -u johndoe -e [email protected] --exclude "github.com, live.com"
./credmap.py -u johndoe -p abc123 -vvv --only "linkedin.com, facebook.com"
./credmap.py -e [email protected] --verbose --proxy "https://127.0.0.1:8080"
./credmap.py --load creds.txt --format "e.u.p"
./credmap.py -l creds.txt -f "u|e:p"
./credmap.py -l creds.txt
./credmap.py --list
L'aggiunta di nuovi siti web da testare con credmap può essere fatta creando un nuovo file XML nella cartella websites/. Per visualizzare un elenco di tutti i possibili tag che possono essere usati nel file XML, fare riferimento alla Wiki.
Costruisci e distribuisci con il seguente:
git clone https://github.com/lightos/credmap.git
cd credmap
docker build -t credmap .
docker run -it credmap