Password Breach Hunting & Email OSINT tool

Hacking Truth
1

Password Breach Hunting & Email OSINT tool


So today we will know about the open source tool that helps in find Password Breach Hunting & Email OSINT tool. This tool is scripted in python language as you can tell -_- you can help us by subscribing to our youtube channel :. Kumar Atul Jaiswal .: before using the too.


h8mail


h8mail is an email OSINT and breach hunting tool using different breach and reconnaissance services, or local breaches such as Troy Hunt's "Collection1" and the infamous "Breach Compilation" torrent. Password Breach Hunting & Email OSINT tool





Features


1) Email pattern matching (reg exp), useful for reading from other tool outputs.

2) Pass URLs to directly find and target emails in pages

3) Loosey patterns for local searchs ("john.smith", "evilcorp")

4)Painless install. Available through pip, only requires requests

5) Bulk file-reading for targeting

6) Output to CSV file

7) Compatible with the "Breach Compilation" torrent scripts

8)Search cleartext and compressed .gz files locally using multiprocessing

    cyclone Compatible with "Collection#1"


9) Get related emails

10) Chase related emails by adding them to the ongoing search

11) Supports premium lookup services for advanced users

12) Custom query premium APIs. Supports username, hash, ip, domain and password and more


13) Regroup breach results for all targets and methods

14)Includes option to hide passwords for demonstrations

15) Delicious colors


How To Install ?


Sudo pip3 install h8mail







For Help Command

h8mail  -h


Usage

1) Query for a single target

$ h8mail -t target@example.com


 h8mail -t example@example.com

 h8mail -t cis@amazon.com
 
 h8mail -t primary@amazon.com


  

Password Breach Hunting & Email OSINT tool



 

2)Query for list of targets, indicate config file for API keys, output to pwned_targets.csv

$ h8mail -t targets.txt -c config.ini -o pwned_targets.csv



3)Query a list of targets against local copy of the Breach Compilation, pass API keys for Snusbase from the command line

$ h8mail -t targets.txt -bc ../Downloads/BreachCompilation/ -k "snusbase_url=$snusbase_url,snusbase_token=$snusbase_token"

 


4)Query without making API calls against local copy of the Breach Compilation

$ h8mail -t targets.txt -bc ../Downloads/BreachCompilation/ -sk



5)Search every .gz file for targets found in targets.txt locally

$ h8mail -t targets.txt -gz /tmp/Collection1/ -sk



6)Check a cleartext dump for target. Add the next 10 related emails to targets to check. Read keys from CLI

$ h8mail -t admin@evilcorp.com -lb /tmp/4k_Combo.txt -ch 10 -k "hunterio=ABCDE123"






7)Query username. Read keys from CLI

$ h8mail -t JSmith89 -q username -k "dehashed_email=user@email.com" "dehashed_key=ABCDE123"



8)Query IP. Chase all related targets. Read keys from CLI

$ h8mail -t 42.202.0.42 -q ip -c h8mail_config_priv.ini -ch 2 --power-chase





9)Fetch URL content (CLI + file). Target all found emails

$ h8mail -u "https://pastebin.com/raw/kQ6WNKqY" "list_of_urls.txt"




Disclaimer

This was written for educational purpose and pentest only.
The author will not be responsible for any damage ..!
The author of this tool is not responsible for any misuse of the information.
You will not misuse the information to gain unauthorized access.
This information shall only be used to expand knowledge and not for causing  malicious or damaging attacks. Performing any hacks without written permission is illegal ..!


All video’s and tutorials are for informational and educational purposes only. We believe that ethical hacking, information security and cyber security should be familiar subjects to anyone using digital information and computers. We believe that it is impossible to defend yourself from hackers without knowing how hacking is done. The tutorials and videos provided on www.hackingtruth.in is only for those who are interested to learn about Ethical Hacking, Security, Penetration Testing and malware analysis. Hacking tutorials is against misuse of the information and we strongly suggest against it. Please regard the word hacking as ethical hacking or penetration testing every time this word is used.


All tutorials and videos have been made using our own routers, servers, websites and other resources, they do not contain any illegal activity. We do not promote, encourage, support or excite any illegal activity or hacking without written permission in general. We want to raise security awareness and inform our readers on how to prevent themselves from being a victim of hackers. If you plan to use the information for illegal purposes, please leave this website now. We cannot be held responsible for any misuse of the given information.



- Hacking Truth by Kumar Atul Jaiswal


Video Tutorial :- SooN

 



Post a Comment

1 Comments
* Please Don't Spam Here. All the Comments are Reviewed by Admin.
Post a Comment
Our website uses cookies to enhance your experience. Learn More
Accept !