
이메일 OSINT 및 비밀번호 유출 사냥 도구, 로컬 또는 프리미엄 서비스 사용. 관련 이메일 추적 지원.
h8mail은 다양한 침해 및 정찰 서비스 또는 Troy Hunt의 "Collection1"과 악명 높은 "Breach Compilation" 토렌트 같은 로컬 침해 데이터를 활용하는 이메일 OSINT 및 침해 헌팅 도구입니다.
pip을 통해 사용 가능, requests만 필요pip3 install h8mail🔑 - API 키 필요
usage: h8mail [-h] [-t USER_TARGETS [USER_TARGETS ...]]
[-u USER_URLS [USER_URLS ...]] [-q USER_QUERY] [--loose]
[-c CONFIG_FILE [CONFIG_FILE ...]] [-o OUTPUT_FILE]
[-j OUTPUT_JSON] [-bc BC_PATH] [-sk]
[-k CLI_APIKEYS [CLI_APIKEYS ...]]
[-lb LOCAL_BREACH_SRC [LOCAL_BREACH_SRC ...]]
[-gz LOCAL_GZIP_SRC [LOCAL_GZIP_SRC ...]] [-sf]
[-ch [CHASE_LIMIT]] [--power-chase] [--hide] [--debug]
[--gen-config]
Email information and password lookup tool
optional arguments:
-h, --help show this help message and exit
-t USER_TARGETS [USER_TARGETS ...], --targets USER_TARGETS [USER_TARGETS ...]
Either string inputs or files. Supports email pattern
matching from input or file, filepath globing and
multiple arguments
-u USER_URLS [USER_URLS ...], --url USER_URLS [USER_URLS ...]
Either string inputs or files. Supports URL pattern
matching from input or file, filepath globing and
multiple arguments. Parse URLs page for emails.
Requires http:// or https:// in URL.
-q USER_QUERY, --custom-query USER_QUERY
Perform a custom query. Supports username, password,
ip, hash, domain. Performs an implicit "loose" search
when searching locally
--loose Allow loose search by disabling email pattern
recognition. Use spaces as pattern seperators
-c CONFIG_FILE [CONFIG_FILE ...], --config CONFIG_FILE [CONFIG_FILE ...]
Configuration file for API keys. Accepts keys from
Snusbase, WeLeakInfo, Leak-Lookup, HaveIBeenPwned,
Emailrep, Dehashed and hunterio
-o OUTPUT_FILE, --output OUTPUT_FILE
File to write CSV output
-j OUTPUT_JSON, --json OUTPUT_JSON
File to write JSON output
-bc BC_PATH, --breachcomp BC_PATH
Path to the breachcompilation torrent folder. Uses the
query.sh script included in the torrent
-sk, --skip-defaults Skips Scylla and HunterIO check. Ideal for local scans
-k CLI_APIKEYS [CLI_APIKEYS ...], --apikey CLI_APIKEYS [CLI_APIKEYS ...]
Pass config options. Supported format: "K=V,K=V"
-lb LOCAL_BREACH_SRC [LOCAL_BREACH_SRC ...], --local-breach LOCAL_BREACH_SRC [LOCAL_BREACH_SRC ...]
Local cleartext breaches to scan for targets. Uses
multiprocesses, one separate process per file, on
separate worker pool by arguments. Supports file or
folder as input, and filepath globing
-gz LOCAL_GZIP_SRC [LOCAL_GZIP_SRC ...], --gzip LOCAL_GZIP_SRC [LOCAL_GZIP_SRC ...]
Local tar.gz (gzip) compressed breaches to scans for
targets. Uses multiprocesses, one separate process per
file. Supports file or folder as input, and filepath
globing. Looks for 'gz' in filename
-sf, --single-file If breach contains big cleartext or tar.gz files, set
this flag to view the progress bar. Disables
concurrent file searching for stability
-ch [CHASE_LIMIT], --chase [CHASE_LIMIT]
Add related emails from hunter.io to ongoing target
list. Define number of emails per target to chase.
Requires hunter.io private API key if used without
power-chase
--power-chase Add related emails from ALL API services to ongoing
target list. Use with --chase
--hide Only shows the first 4 characters of found passwords
to output. Ideal for demonstrations
--debug Print request debug information
--gen-config, -g Generates a configuration file template in the current
working directory & exits. Will overwrite existing
h8mail_config.ini file
$ h8mail -t [email protected]
pwned_targets.csv로 출력$ h8mail -t targets.txt -c config.ini -o pwned_targets.csv
$ h8mail -t targets.txt -bc ../Downloads/BreachCompilation/ -k "snusbase_token=$snusbase_token"
$ h8mail -t targets.txt -bc ../Downloads/BreachCompilation/ -sk
$ h8mail -t targets.txt -gz /tmp/Collection1/ -sk
$ h8mail -t [email protected] -lb /tmp/4k_Combo.txt -ch 10 -k "hunterio=ABCDE123"
$ h8mail -t JSmith89 -q username -k "[email protected]" "dehashed_key=ABCDE123"
$ h8mail -t 42.202.0.42 -q ip -c h8mail_config_priv.ini -ch 2 --power-chase
$ h8mail -u "https://pastebin.com/raw/kQ6WNKqY" "list_of_urls.txt"
💜 h8mail은 다음에서 찾을 수 있습니다:
k at khast3x dot club(PGP 지원)으로 이메일을 보내주시기 바랍니다.# curl + gpg 프로 팁: ktx의 키 가져오기
curl https://keybase.io/ktx/pgp_keys.asc | gpg --import
# Keybase 앱은 gpg 키체인에 키를 푸시할 수도 있습니다.
keybase pgp pull ktx
이 프로젝트에 대한 최신 소식을 받아보고 싶다면:
| 서비스 | 기능 | 상태 |
|---|
| HaveIBeenPwned(v3) | 이메일 침해 횟수 | ✅ 🔑 |
| HaveIBeenPwned Pastes(v3) | 대상을 언급한 텍스트 파일 URL | ✅ 🔑 |
| Hunter.io - 공개 | 관련 이메일 수 | ✅ |
| Hunter.io - 서비스 (무료 티어) | 일반 텍스트 관련 이메일, 추적 | ✅ 🔑 |
| Snusbase - 서비스 | 일반 텍스트 비밀번호, 해시 및 솔트, 사용자 이름, IP - 빠름 ⚡ | ✅ 🔑 |
| Leak-Lookup - 공개 | 검색 가능한 침해 결과 수 | ✅ (🔑) |
| Leak-Lookup - 서비스 | 일반 텍스트 비밀번호, 해시 및 솔트, 사용자 이름, IP, 도메인 | ✅ 🔑 |
| Emailrep.io - 서비스 (무료) | 마지막으로 침해에 노출된 시간, 소셜 미디어 프로필 | ✅ 🔑 |
| scylla.so - 서비스 (무료) | 일반 텍스트 비밀번호, 해시 및 솔트, 사용자 이름, IP, 도메인 | 🚧 |
| Dehashed.com - 서비스 | 일반 텍스트 비밀번호, 해시 및 솔트, 사용자 이름, IP, 도메인 | ✅ 🔑 |
| IntelX.io - 서비스 (무료 평가판) | 일반 텍스트 비밀번호, 해시 및 솔트, 사용자 이름, IP, 도메인, 비트코인 지갑, IBAN | ✅ 🔑 |
| 🆕 Breachdirectory.org - 서비스 (무료) | 일반 텍스트 비밀번호, 해시 및 솔트, 사용자 이름, 도메인 | 🚧 🔑 |