Closed Ekultek closed 5 years ago
Hey there,
Thank you for opening the issue.
Have you tried using -gz
on the file before extracting the tar archive? Typically when it is still .tar.gz
.
Also, can you try using zgrep
against your compressed archive to find your target?
Glad to know you're using the WhatBreach/h8mail combo, I think we're slowly setting a new standard!
Cheers
Hey, yeah it's the same problem.
I figured this out, it was my fault not the tools, thanks!
Roger that, thanks!
Description
False negatives while doing compressed file searching
What I Did
Obviously I use whatbreach to get my databases (because i'm cool like that ;p). Anyways
austinfields7@hotmail.com
has been breached in one of Adobe's breaches, this file is atar.gz
that decompressed to agz
file that decompresses to a file namedcred
while using h8mail to search through the file it will not provide any information, but it will show that there are occurrences if i use-lb
.