Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
pwned — Have I Been Pwned APIに問い合わせて、漏洩したアカウント、ペースト、パスワード露出を確認し、侵害された認証情報の迅速なセキュリティ評価を可能にするCLIツール。 | Kitploit
ツール/GitHubGitHub/wkovacs64/pwned
OSINT (オープンソースインテリジェンス)パスワードクラッキング脆弱性分析情報収集
GitHubwkovacs64/pwned

pwned

Have I Been Pwned APIに問い合わせて、漏洩したアカウント、ペースト、パスワード露出を確認し、侵害された認証情報の迅速なセキュリティ評価を可能にするCLIツール。

リポジトリを見るウェブサイト
247261日前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
ロゴ

pwned

Troy Hunt氏のHave I been pwned?サービスを照会するためのコマンドラインツールで、hibp Node.jsモジュールを使用しています。

npm Version Build Status

インストール

Node.jsをダウンロードしてインストールし、npmを使用してpwnedをグローバルにインストールしてください:

root@kitploit:~
npm install pwned -g

または、npxパッケージランナーを使用してオンデマンドで実行することもできます:

root@kitploit:~
npx pwned

保護されたコマンド

2019年7月18日、haveibeenpwned.com APIはいくつかのサービスを認証の後ろに移行し、APIキーが必要になりました。理由と詳細な説明についてはTroyのブログ記事を参照してください。pwnedの一部のコマンド(例:ba、pa、search)を使用するには、APIキーを取得し、pwned apiKeyを実行してpwnedを設定する必要があります。その他のコマンドはAPIキーを必要としないため、キーを取得しなくても使用できます。

使い方

root@kitploit:~
pwned <command>

Commands:
  pwned apiKey [key]            set the API key to be used for authenticated requests
  pwned ba <account|email>      get all breaches for an account (username or email address)
  pwned bd <domain>             get all breached email addresses for a domain
  pwned breach <name>           get a single breached site by breach name
  pwned breaches                get all breaches in the system
  pwned dc                      get all data classes in the system
  pwned lb                      get the most recently added breach
  pwned pa <email>              get all pastes for an account (email address)
  pwned pw <password>           securely check a password for public exposure
  pwned sd                      get all subscribed domains for your account
  pwned search <account|email>  search breaches and pastes for an account (username or email
                                address)
  pwned slbe <email>            get all stealer log domains for an email address
  pwned slbed <email-domain>    get all stealer log email aliases for an email domain
  pwned slbwd <website-domain>  get all stealer log email addresses for a website domain
  pwned subStatus               get the subscription status of your API key

Options:
  -h, --help     Show help                                                                 [boolean]
  -v, --version  Show version number                                                       [boolean]

例

アカウントのすべての侵害を取得:

root@kitploit:~
$ pwned ba [email protected]
✔ Good news — no pwnage found!

システム内のすべての侵害を取得し、結果を'adobe.com'ドメインのみにフィルタリング:

root@kitploit:~
$ pwned breaches -d adobe.com
-
  Title:        Adobe
  Name:         Adobe
  Domain:       adobe.com
  BreachDate:   2013-10-04
  AddedDate:    2013-12-04T00:00:00Z
  ModifiedDate: 2013-12-04T00:00:00Z
  PwnCount:     152445165
  Description:  In October 2013, 153 million Adobe accounts were breached with each containing an internal ID, username, email, <em>encrypted</em> password and a password hint in plain text. The password cryptography was poorly done and <a href="http://stricture-group.com/files/adobe-top100.txt" target="_blank" rel="noopener">many were quickly resolved back to plain text</a>. The unencrypted hints also <a href="http://www.troyhunt.com/2013/11/adobe-credentials-and-serious.html" target="_blank" rel="noopener">disclosed much about the passwords</a> adding further to the risk that hundreds of millions of Adobe customers already faced.
  DataClasses:
    - Email addresses
    - Password hints
    - Passwords
    - Usernames
  IsVerified:   true
  IsFabricated: false
  IsSensitive:  false
  IsActive:     true
  IsRetired:    false
  IsSpamList:   false
  LogoType:     svg

侵害名で単一の侵害サイトを取得:

root@kitploit:~
$ pwned breach MyCompany
✔ No breach found by that name.

システム内のすべてのデータクラスを取得し、外部/連鎖的な利用のために生のJSON結果を返す:

root@kitploit:~
$ pwned dc --raw
["Account balances","Address book contacts","Age groups","Ages","Apps installed on devices","Astrological signs","Auth tokens","Avatars","Bank account numbers","Banking PINs","Beauty ratings","Biometric data","Browser user agent details","Buying preferences","Car ownership statuses","Career levels","Cellular network names","Charitable donations","Chat logs","Credit card CVV","Credit cards","Credit status information","Customer feedback","Customer interactions","Dates of birth","Deceased date","Deceased statuses","Device information","Device usage tracking data","Drinking habits","Drug habits","Eating habits","Education levels","Email addresses","Email messages","Employers","Ethnicities","Family members' names","Family plans","Family structure","Financial investments","Financial transactions","Fitness levels","Genders","Geographic locations","Government issued IDs","Health insurance information","Historical passwords","Home ownership statuses","Homepage URLs","IMEI numbers","IMSI numbers","Income levels","Instant messenger identities","IP addresses","Job titles","MAC addresses","Marital statuses","Names","Nationalities","Net worths","Nicknames","Occupations","Parenting plans","Partial credit card data","Passport numbers","Password hints","Passwords","Payment histories","Payment methods","Personal descriptions","Personal health data","Personal interests","Phone numbers","Physical addresses","Physical attributes","Political donations","Political views","Private messages","Professional skills","Profile photos","Purchases","Purchasing habits","Races","Recovery email addresses","Relationship statuses","Religions","Reward program balances","Salutations","School grades (class levels)","Security questions and answers","Sexual fetishes","Sexual orientations","Smoking habits","SMS messages","Social connections","Social media profiles","Spoken languages","Support tickets","Survey results","Time zones","Travel habits","User statuses","User website URLs","Usernames","Utility bills","Vehicle details","Website activity","Work habits","Years of birth","Years of professional experience"]

メールアドレスのすべてのペーストを取得:

root@kitploit:~
$ pwned pa [email protected]
-
  Source:     Pastebin
  Id:         YrpQA60S
  Title:      null
  Date:       2018-01-24T07:54:15Z
  EmailCount: 16476
-
  Source:     Pastebin
  Id:         suPshHZ1
  Title:      null
  Date:       2017-09-06T03:41:33Z
  EmailCount: 20444
-
  Source:     Pastebin
  Id:         xyb8vavK
  Title:      null
  Date:       2015-06-01T00:16:46Z
  EmailCount: 8
-
  Source:     Pastebin
  Id:         DaaFj8Be
  Title:      CrackingCore - Redder04
  Date:       2015-04-05T22:22:39Z
  EmailCount: 116
-
  Source:     Pastebin
  Id:         9MAAgecd
  Title:      IPTV Yabancı Combolist
  Date:       2015-02-07T15:21:00Z
  EmailCount: 244
-
  Source:     Pastebin
  Id:         QMx1dPUT
  Title:      null
  Date:       2015-02-02T20:45:00Z
  EmailCount: 6607
-
  Source:     Pastebin
  Id:         zUFSee4n
  Title:      nethingoez
  Date:       2015-01-21T15:13:00Z
  EmailCount: 312
-
  Source:     AdHocUrl
  Id:         http://siph0n.in/exploits.php?id=4560
  Title:      BuzzMachines.com 40k+
  Date:       null
  EmailCount: 36959
-
  Source:     AdHocUrl
  Id:         http://siph0n.in/exploits.php?id=4737
  Title:      PayPalSucks Database 102k
  Date:       null
  EmailCount: 82071
-
  Source:     AdHocUrl
  Id:         http://balockae.online/files/BlackMarketReloaded_users.sql
  Title:      balockae.online
  Date:       null
  EmailCount: 10547

データ侵害で公開されたかどうかを安全に確認するためにパスワードをチェック:

root@kitploit:~
$ pwned pw Password1234
⚠ Oh no — pwned 3360 times!

アカウントの侵害とペーストの両方を検索(侵害データは省略):

root@kitploit:~
$ pwned search nobody
breaches:
  -
    Name: BattlefieldHeroes
  -
    Name: CannabisForum
  -
    Name: Forbes
  -
    Name: Gawker
  -
    Name: HackForums
  -
    Name: LoungeBoard
  -
    Name: PokemonCreed
  -
    Name: Win7Vista
pastes:   null

ライセンス

このツールはMITライセンスの下で配布されています。

ツールをダウンロード