OSINT Tool for Finding Passwords of Compromised Email Accounts
Created by Lohitya Pushkar (thewhiteh4t).
Twitter
-
Blog
| Available | in | |
| ----------------------------------------- | ------------------------------------ | ------------------------------------------------- |
| [BlackArch Linux](https://blackarch.org/) | [SecBSD](https://secbsd.org/) | [Tsurugi Linux](https://tsurugi-linux.org/) |
| | | |
---
pwnedOrNot works in two phases. In the **first** phase it tests the given email address using [**`HaveIBeenPwned v3 API`**](https://haveibeenpwned.com/API/v3) to find if the account have been breached in the past and in the **second** phase it searches the **password** in available **public dumps**.
> [!IMPORTANT]
> An API Key is required to use the tool. You can purchase a key from HIBP website linked below
https://haveibeenpwned.com/API/v3
---
## Featured
OSINT Collection Tools for Pastebin - Jake Creps
eForensics Magazine May 2020
---
## Changelog
https://github.com/thewhiteh4t/pwnedOrNot/wiki/Changelog
---
## Features
[**haveibeenpwned**](https://haveibeenpwned.com/API/v3) offers a lot of information about the compromised email, pwnedOrNot displays most useful information such as :
- Name of Breach
- Domain Name
- Date of Breach
- Fabrication status
- Verification Status
- Retirement status
- Spam Status
### About Passwords
The chances of finding passwords depends upon the following factors :
- If public dumps are available for the email address
- If the public dumps are accessible
- Sometimes the dumps are removed
- If the public dump contains password
- Sometimes a dump contains only email addresses
#### Tested on
- **Kali Linux**
- **BlackArch Linux**
- **Kali Nethunter**
- **Termux**
> Windows users are suggested to use Kali Linux WSL2 or a VM
## Installation
**Ubuntu / Kali Linux / Nethunter / Termux**
```bash
git clone https://github.com/thewhiteh4t/pwnedOrNot.git
cd pwnedOrNot
chmod +x install.sh
./install.sh
```
**BlackArch Linux**
```bash
pacman -S pwnedornot
```
**Docker**
```bash
git clone https://github.com/thewhiteh4t/pwnedOrNot.git
docker build -t pon .
docker run -it pon
```
## Updates
```bash
cd pwnedOrNot
git pull
```
## Usage
```
…
```
### Add API key
```
# Using ENV variable :
export PWNED_API_KEY=""
# Using CLI argument :
python3 pwnedornot.py -e
[email protected] -k
# Using config file :
nano ~/.config/pwnedornot/config.json
{
"api_key": ""
}
```
### Examples
```
…
```
## Demo