Tagged: OSINT
10 posts · browse all tags
-
24 Billion Credentials, 36 Sources, and 27 Records Actually Tagged "Redline"
Headlines called it the biggest credential leak in history. The researchers who found it can't say how many duplicates it contains or who ran the database. Here's what's verifiably inside the "24 billion password leak," and why one real detail matters more than the headline number.
-
Checking Your Own Public Footprint Part 1: Why Registrars, Defaults, and Time All Drift
A practical series on auditing what's publicly known about you: domain records, usernames, code, and history. Part 1 covers why the audit is worth doing at all, even if nothing has gone wrong yet.
-
Checking Your Own Public Footprint Part 2: Reading Your Own WHOIS, RDAP, and Certificate History
A walkthrough of the whois command, how .uk individual privacy actually works, how RDAP bootstrapping finds the right server, and pulling your own certificate transparency history from crt.sh.
-
Checking Your Own Public Footprint Part 3: What a Username Reveals, and How to Check It Safely
Using Maigret to check what accounts are tied to a username, run against a purpose-built decoy identity rather than a real handle, and why an automated match count needs a second look before you trust it.
-
Checking Your Own Public Footprint Part 4: Code, Secrets, and What's Sitting in Your Own Repos
Scanning your own public repositories for leaked secrets with gitleaks and TruffleHog, checking what's publicly indexed about your own IP space with Shodan's InternetDB, and what's hiding in a file's metadata.
-
Checking Your Own Public Footprint Part 5: The Wayback Machine, Dorking, and a Safe Way to Check Breaches
Finding stale pre-privacy WHOIS snapshots on the Wayback Machine, basic search-engine dorking against your own name, and checking passwords against real breach data without ever sending the password anywhere.
-
Checking Your Own Public Footprint Part 6: Closing the Gaps You Just Found
The actual registrar privacy toggle, the Nominet individual opt-out request, requesting removal of a stale archived page, and the general hygiene changes worth making once, not per finding.
-
Checking Your Own Public Footprint Part 7: Automating the Whole Audit With SpiderFoot
SpiderFoot automates most of what this series just did by hand in one pass. What it actually wraps, what it still can't do for you, and a short checklist to run the whole audit yourself.
-
Sn1per Deep Dive Part 2: What Discover and Recon Mode Actually Run
Sn1per's discover and recon modes chain together nmap, Amass, Subfinder, Sublist3r, crt.sh, and Shodan into one deduplicated target list. Read directly from the Community Edition source, with a real correction from root-verified testing.
-
Password Cracking and Wordlist Engineering Part 4: Building Wordlists That Actually Work
rockyou.txt is fourteen million real, breached passwords from 2009 — and it's the wrong tool the moment a target has any pattern to its passwords at all. Verified cewl and crunch syntax for building wordlists that actually match how a specific organization names things.