WebBreacher / WhatsMyName

This repository has the JSON file required to perform user enumeration on various websites.
https://whatsmyname.app/
Other
1.73k stars 293 forks source link

whats-my-name.py on Ubuntu WSL2 no results #568

Closed ZerberusSec closed 2 years ago

ZerberusSec commented 2 years ago

My plan was to create a Maltego transform for a soon published open OSINT-community iTDS Server. I tried to test first on Ubuntu.

I get to real results on the console output - but probably Iam doing somethign wrong.

System: Ubuntu on WSL2 (Windows 10) With preinstalled Python3.8. Using venv, only installed the requirements.txt

Command: python WhatsMyName/whats_my_name.py -u hopefullynouserwiththisname

Desired behaviour: Get output with simmilar results as on whatsmyname.app

The output only gives me a list of status-codes from webpages. It does not matter if I input some random - probably non existing username-string, or a username where I definetly know its registered on various checked pages.

Is it a error on my side? Did I miunderstood something?

Here is my output:

(whatsmyname) user@user-machine:~$ python3 WhatsMyName/whats_my_ -u hopefullynouserwiththisname
Can not load response cookies: Illegal key '@cameo/homepageSeed'
Can not load response cookies: Illegal key '@cameo/sessionIdentifier'
Can not load response cookies: Illegal key '@cameo/vid'
Can not load response cookies: Illegal key '@cameo/lang'
Site Connection Error Furiffic
+------------------------------+----------------------------------------------------------------------------------------------------------------------+------------+--------+
| Site Name                    | Url                                                                                                                  | Category   | Result |
+------------------------------+----------------------------------------------------------------------------------------------------------------------+------------+--------+
| 1001mem                      | http://1001mem.ru/hopefullynouserwiththisname                                                                        | social     | 200    |
| 3DNews                       | http://forum.3dnews.ru/member.php?username=hopefullynouserwiththisname                                               | social     | 200    |
| ACF                          | https://support.advancedcustomfields.com/forums/users/hopefullynouserwiththisname                                    | coding     | 200    |
| BDSMLR                       | https://hopefullynouserwiththisname.bdsmlr.com                                                                       | XXXPORNXXX | 200    |
| bitcoin forum                | https://bitcoinforum.com/profile/hopefullynouserwiththisname                                                         | finance    | 200    |
| blogi.pl                     | https://www.blogi.pl/osoba,hopefullynouserwiththisname.html                                                          | blog       | 200    |
| Blogmarks                    | http://blogmarks.net/user/hopefullynouserwiththisname                                                                | misc       | 200    |
| BodyBuilding.com             | http://bodyspace.bodybuilding.com/hopefullynouserwiththisname/                                                       | health     | 200    |
| boosty                       | https://boosty.to/hopefullynouserwiththisname                                                                        | social     | 200    |
| datezone                     | https://www.datezone.com/users/hopefullynouserwiththisname/                                                          | XXXPORNXXX | 200    |
| Destructoid                  | https://www.destructoid.com/?name=hopefullynouserwiththisname                                                        | social     | 200    |
| diigo                        | https://www.diigo.com/profile/hopefullynouserwiththisname                                                            | images     | 200    |
| Duolingo                     | https://www.duolingo.com/profile/hopefullynouserwiththisname                                                         | hobby      | 200    |
| easyen                       | https://easyen.ru/index/8-0-hopefullynouserwiththisname                                                              | social     | 200    |
| FanCentro                    | https://fancentro.com/hopefullynouserwiththisname/                                                                   | XXXPORNXXX | 200    |
| Fark                         | https://www.fark.com/users/hopefullynouserwiththisname                                                               | social     | 200    |
| fansly                       | https://fansly.com/hopefullynouserwiththisname/posts                                                                 | XXXPORNXXX | 200    |
| fcv                          | https://fcv.if.ua/index.php/component/comprofiler/userprofile/hopefullynouserwiththisname/                           | hobby      | 200    |
| fotka                        | https://fotka.com/profil/hopefullynouserwiththisname                                                                 | social     | 200    |
| FurAffinity                  | https://www.furaffinity.net/user/hopefullynouserwiththisname                                                         | XXXPORNXXX | 200    |
| Garmin connect               | https://connect.garmin.com/modern/profile/hopefullynouserwiththisname                                                | health     | 200    |
| getmonero                    | https://forum.getmonero.org/user/hopefullynouserwiththisname                                                         | misc       | 200    |
| Gettr                        | https://api.gettr.com/s/user/hopefullynouserwiththisname/exist                                                       | social     | 200    |
| Hacker News                  | https://news.ycombinator.com/user?id=hopefullynouserwiththisname                                                     | tech       | 200    |
| hackerearth                  | https://www.hackerearth.com/@hopefullynouserwiththisname                                                             | coding     | 200    |
| hamaha                       | https://hamaha.net/hopefullynouserwiththisname                                                                       | finance    | 200    |
| hiberworld                   | https://hiberworld.com/u/hopefullynouserwiththisname                                                                 | gaming     | 200    |
| Hubski                       | https://hubski.com/user/hopefullynouserwiththisname                                                                  | social     | 200    |
| igromania                    | http://forum.igromania.ru/member.php?username=hopefullynouserwiththisname                                            | social     | 200    |
| imagefap                     | https://www.imagefap.com/profile/hopefullynouserwiththisname                                                         | XXXPORNXXX | 200    |
| Internet Archive User Search | https://archive.org/search.php?query=hopefullynouserwiththisname                                                     | misc       | 200    |
| interpals                    | https://www.interpals.net/hopefullynouserwiththisname                                                                | dating     | 200    |
| jeja.pl                      | https://www.jeja.pl/user,hopefullynouserwiththisname                                                                 | misc       | 200    |
| Joe Monster                  | https://joemonster.org/bojownik/hopefullynouserwiththisname                                                          | misc       | 200    |
| LibraryThing                 | https://www.librarything.com/profile/hopefullynouserwiththisname                                                     | hobby      | 200    |
| MANYVIDS                     | https://www.manyvids.com/results.php?keywords=hopefullynouserwiththisname                                            | XXXPORNXXX | 200    |
| Maroc_nl                     | https://www.maroc.nl/forums/members/hopefullynouserwiththisname.html                                                 | social     | 200    |
| Massage Anywhere             | https://www.massageanywhere.com/profile/hopefullynouserwiththisname                                                  | health     | 200    |
|                   |                                                                   | health     | 200    |
| metacritic                   |                                                           | hobby      | 200    |
| Minecraft List               |                                                         | gaming     | 200    |
| Mixi                         | .pl?id=hopefullynouserwiththisname                                                     | social     | 200    |
| moxfield                     |                                                            | misc       | 200    |
| Muck Rack                    |                                                                      | news       | 200    |
| naija_planet                 |                                                                   | dating     | 200    |
| NaturalNews                  |                                                           | political  | 200    |
| newmeet                      |                                                        | dating     | 200    |
| Opencollective               |                                                                | finance    | 200    |
| OPGG                         |                                                         | gaming     | 200    |
| Parler archived profile      | .com/profile/hopefullynouserwiththisname                                 | archived   | 200    |
| Parler archived posts        | .com/profile/hopefullynouserwiththisname/posts                           | archived   | 200    |
| PhotoBucket                  |                                                             | images     | 200    |
| Pinterest                    |                                                                | social     | 200    |
| Playstation Network          |                                                | gaming     | 200    |
| Plurk                        |                                                                     | social     | 200    |
| Polchat.pl                   |                                                         | social     | 200    |
| policja2009                  | .php?search_author=hopefullynouserwiththisname                                  | misc       | 200    |
| popl                         |                                                                         | business   | 200    |
| ReblogMe                     |                                                                      | XXXPORNXXX | 200    |
| Roblox                       | .000Z | gaming     | 200    |
| Ruby Dating                  |                                                              | dating     | 200    |
| smule                        |                                                                    | music      | 200    |
| Snapchat                     |                                                              | social     | 200    |
| Steam                        |                                                             | gaming     | 200    |
|                    |                                                                      | social     | 200    |
| tabletoptournament           |                                             | misc       | 200    |
| Teknik                       |                                                                    | tech       | 200    |
| Telegram                     |                                                                              | social     | 200    |
| TikTok                       |                                                           | social     | 200    |
| Tinder                       |                                                                       | dating     | 200    |
| TrackmaniaLadder             | .php                                                        | gaming     | 200    |
| Twitter archived profile     | .com/hopefullynouserwiththisname                                        | archived   | 200    |
| Twitter archived tweets      | */*                               | archived   | 200    |
| twoplustwo                   | .php                                                                        | hobby      | 200    |
| VIP-blog                     |                                                                       | blog       | 200    |
| Virustotal                   |                                                       | misc       | 200    |
| Voice123                     |                                                                      | hobby      | 200    |
| weibo                        |                                                                      | social     | 200    |
| Wikidot                      |                                                          | social     | 200    |
| Wikipedia                    |                                                        | news       | 200    |
| zhihu                        |                                                              | social     | 200    |
+------------------------------+----------------------------------------------------------------------------------------------------------------------+------------+--------+
WebBreacher commented 2 years ago

Hey @yooper, can you look into this? Looks like it might be showing all results instead of just found. I thought me made the default for the script only show found and not all?

yooper commented 2 years ago

@WebBreacher , The PR https://github.com/WebBreacher/WhatsMyName/pull/567 should resolve this issue. It truncates the pretty urls down to 50 characters in width.

WebBreacher commented 2 years ago

@yooper I don't think the wrapping is what is the issue here. @ZerberusSec submitted a username that should not exist on these sites. The script looks like it is returning all results instead of just the sites that matched (which should be the default).

yooper commented 2 years ago

I am tracking now.. when I run the command in ubuntu 20,

 python whats_my_name.py -u hopefullynouserwiththisname|wc
Can not load response cookies: Illegal key '@cameo/homepageSeed'
Can not load response cookies: Illegal key '@cameo/sessionIdentifier'
Can not load response cookies: Illegal key '@cameo/vid'
Can not load response cookies: Illegal key '@cameo/lang'
Site Connection Error quitter.pl
     68     606    7344

It is filtering results, but upon inspection some false positives are being returned. I will work on getting the inspect tool working to help us better debug these issues moving forward. Feel free to assign this task to me.

WebBreacher commented 2 years ago

I don't think that all of the issues are the result of bad detection strings/codes.

Can you double check that, by default, only the found sites are being reported in the display?

ZerberusSec commented 2 years ago

I still have this issue. Regarding of using it on Ubuntu WSL or Windows. Iam always seeing all those platform with the "reult" code - most of them 200.

There are no other errors or something.

It does not matter which username I input - I always get those reults shown in the initial ticket.

Last commit of my repo (cloned is yesterday):

commit c03c77ca83eacc60e4c86ed1bbe67182d87a77c9 (HEAD -> main, origin/main, origin/HEAD) Author: WebBreacher WebBreacher@users.noreply.github.com Date: Fri Sep 16 21:58:52 2022 +0000

Minify source code
yooper commented 2 years ago

@ZerberusSec , there has been a fix applied to this issue. Just pull down the latest version and run your command. python whats_my_name.py -u hopefullynouserwiththisname

WebBreacher commented 2 years ago

I checked and it works as desired. Thanks for the quick fix @yooper