soxoj / maigret

πŸ•΅οΈβ€β™‚οΈ Collect a dossier on a person by username from thousands of sites
https://t.me/osint_maigret_bot
MIT License
10.25k stars 793 forks source link

Invalid result for bogus username "ASDFWowReallyNobodyWould7197425ChooseThis" #683

Closed meltingscales closed 1 year ago

meltingscales commented 2 years ago

Invalid link: See below. I'm pretty sure noone has the username ASDFWowReallyNobodyWould7197425ChooseThis.

$ go run maigret.go ASDFWowReallyNobodyWould7197425ChooseThis
Investigating ASDFWowReallyNobodyWould7197425ChooseThis on:
[+] Pinterest: https://www.pinterest.com/ASDFWowReallyNobodyWould7197425ChooseThis/
[+] NameMC (Minecraft.net skins): https://namemc.com/profile/ASDFWowReallyNobodyWould7197425ChooseThis
[+] Quora: https://www.quora.com/profile/ASDFWowReallyNobodyWould7197425ChooseThis
[+] Cent: https://beta.cent.co/@ASDFWowReallyNobodyWould7197425ChooseThis
[+] Facebook: https://www.facebook.com/ASDFWowReallyNobodyWould7197425ChooseThis
[+] babyRU: https://www.baby.ru/u/ASDFWowReallyNobodyWould7197425ChooseThis/
[+] GuruShots: https://gurushots.com/ASDFWowReallyNobodyWould7197425ChooseThis/photos
[+] AllTrails: https://www.alltrails.com/members/ASDFWowReallyNobodyWould7197425ChooseThis
[+] Instagram: https://www.instagram.com/ASDFWowReallyNobodyWould7197425ChooseThis
[+] Gumroad: https://www.gumroad.com/ASDFWowReallyNobodyWould7197425ChooseThis
[+] opennet: https://www.opennet.ru/~ASDFWowReallyNobodyWould7197425ChooseThis
[+] Raidforums: https://raidforums.com/User-ASDFWowReallyNobodyWould7197425ChooseThis
[+] Codecademy: https://www.codecademy.com/profiles/ASDFWowReallyNobodyWould7197425ChooseThis
[+] 3dnews: http://forum.3dnews.ru/member.php?username=ASDFWowReallyNobodyWould7197425ChooseThis
[+] Chess: https://www.chess.com/member/ASDFWowReallyNobodyWould7197425ChooseThis
[+] Zhihu: https://www.zhihu.com/people/ASDFWowReallyNobodyWould7197425ChooseThis
[+] Twitter: https://mobile.twitter.com/ASDFWowReallyNobodyWould7197425ChooseThis
[+] Smule: https://www.smule.com/ASDFWowReallyNobodyWould7197425ChooseThis
[+] Clozemaster: https://www.clozemaster.com/players/ASDFWowReallyNobodyWould7197425ChooseThis
[+] Ello: https://ello.co/ASDFWowReallyNobodyWould7197425ChooseThis
[+] CapFriendly: https://www.capfriendly.com/users/ASDFWowReallyNobodyWould7197425ChooseThis
[+] GitHub Support Community: https://github.community/u/ASDFWowReallyNobodyWould7197425ChooseThis/summary
[+] Kali community: https://forums.kali.org/member.php?username=ASDFWowReallyNobodyWould7197425ChooseThis
[+] Whonix Forum: https://forums.whonix.org/u/ASDFWowReallyNobodyWould7197425ChooseThis
[+] igromania: http://forum.igromania.ru/member.php?username=ASDFWowReallyNobodyWould7197425ChooseThis
[+] ProductHunt: https://www.producthunt.com/@ASDFWowReallyNobodyWould7197425ChooseThis
[+] Steamid: https://steamid.uk/profile/ASDFWowReallyNobodyWould7197425ChooseThis
[+] SparkPeople: https://www.sparkpeople.com/mypage.asp?id=ASDFWowReallyNobodyWould7197425ChooseThis
[+] Football: https://www.rusfootball.info/user/ASDFWowReallyNobodyWould7197425ChooseThis/
[+] Countable: https://www.countable.us/ASDFWowReallyNobodyWould7197425ChooseThis
[+] babyblogRU: https://www.babyblog.ru/user/info/ASDFWowReallyNobodyWould7197425ChooseThis
[+] LiveLeak: https://www.liveleak.com/c/ASDFWowReallyNobodyWould7197425ChooseThis
fen0s commented 2 years ago

liveleak and such sites were disabled long ago. is it possible you're using old version of Maigret? try using github version instead of pip package, or one of executables in releases

meltingscales commented 2 years ago

@fen0s Thank you! I will try this.

meltingscales commented 2 years ago

@fen0s Much better. Last time, I was using a Go version of this tool.

New output (Still with some false positives):

$ python3 -m maigret ASDFWowReallyNobodyWould7197425ChooseThis
[-] Starting a search on top 500 sites from the Maigret database...
[!] You can run search by full list of sites with flag `-a`
[*] Checking username ASDFWowReallyNobodyWould7197425ChooseThis on:
[+] Shutterstock: https://www.shutterstock.com/fi/g/ASDFWowReallyNobodyWould7197425ChooseThis/about
[+] Ebay: https://ebay.com/usr/ASDFWowReallyNobodyWould7197425ChooseThis
[+] Waveapps: https://community.waveapps.com/profile/ASDFWowReallyNobodyWould7197425ChooseThis
[+] YandexZenChannel [Yandex]: https://zen.yandex.ru/ASDFWowReallyNobodyWould7197425ChooseThis
[?] TJournal: https://tjournal.ru/search/v2/subsite/relevant?query=ASDFWowReallyNobodyWould7197425ChooseThis
[+] Influenster: https://www.influenster.com/ASDFWowReallyNobodyWould7197425ChooseThis
100%|β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ| 500/500 [00:32<00:00, 15.48it/s]
[-] Restarting checks for 6 sites... (1 attempts left)
100%|β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ| 6/6 [00:30<00:00,  5.03s/it]
[!] Too many errors of type "Access denied" (3.0%)
[!] Too many errors of type "Unsupported username format" (3.0%)
[-] You can see detailed site check errors with a flag `--print-errors`
[*] Short text report:
Search by username ASDFWowReallyNobodyWould7197425ChooseThis returned 5 accounts.
Extended info extracted from 0 accounts.
Countries: us, ca, ru
Interests (tags): music, photo, stock, shopping
fen0s commented 2 years ago

welllll, it's weird, but this is an old version too, because we've fixed Shutterstock and Ebay a few days ago. if you want as little false positives as possible, you gotta update maigret often, because sites change constantly and we have to adapt. perhaps we'll make an autoupdater in future...

meltingscales commented 2 years ago

welllll, it's weird, but this is an old version too, because we've fixed Shutterstock and Ebay a few days ago. if you want as little false positives as possible, you gotta update maigret often, because sites change constantly and we have to adapt. perhaps we'll make an autoupdater in future...

Weird, I'll try running from source on master branch and report back.

MeowyPouncer commented 1 year ago

Any luck on the given problem for now? :)

meltingscales commented 1 year ago

Just tested, looks like there are still some false positive detections.

Perhaps we can write a CICD test that returns a list of detectors that are out of date?

This would be useful for failing CICD each time a detector needs to be updated. Perhaps we can use Github pipelines to do this.

i.e.

#!/usr/bin/env bash
set -euxo pipefail

dummyUsername=ASDFWowReallyNobodyWould7197425ChooseThis

result=$(python3 maigret.py "$dummyUsername")

if [ "${result}" == *"returned 0 accounts"* ]; then
  echo "Success: $dummyUsername not detected."
  exit 0
else
  echo "Failure: $dummyUsername was detected."
  exit 1
fi

Output:

henry@goodra-fz55:~/Git/maigret$ python3 maigret.py  ASDFWowReallyNobodyWould7197425ChooseThis
[-] Starting a search on top 500 sites from the Maigret database...
[!] You can run search by full list of sites with flag `-a`
[*] Checking username ASDFWowReallyNobodyWould7197425ChooseThis on:
[+] Virgool: https://virgool.io/@ASDFWowReallyNobodyWould7197425ChooseThis
[+] Eurogamer: https://www.eurogamer.net/profiles/ASDFWowReallyNobodyWould7197425ChooseThis
[+] Lolchess: https://lolchess.gg/profile/na/ASDFWowReallyNobodyWould7197425ChooseThis
[?] TJournal: https://tjournal.ru/search/v2/subsite/relevant?query=ASDFWowReallyNobodyWould7197425ChooseThis
[+] Folkd: http://www.folkd.com/user/ASDFWowReallyNobodyWould7197425ChooseThis
100%|β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ| 500/500 [00:35<00:00, 14.23it/s]
[-] Restarting checks for 5 sites... (1 attempts left)
100%|β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ| 5/5 [00:30<00:00,  6.04s/it]
[!] Too many errors of type "Just a moment: bot redirect challenge" (3.0%)
[!] Too many errors of type "Unsupported username format" (3.0%)
[-] You can see detailed site check errors with a flag `--print-errors`
[*] Short text report:
Search by username ASDFWowReallyNobodyWould7197425ChooseThis returned 4 accounts.
Extended info extracted from 0 accounts.
Countries: ir, us, kr, eu, in
Interests (tags): blog
MeowyPouncer commented 1 year ago

Thanks for the swift answer and the proposition. We will look into it. Anyway, for now, three out of the five given sites have already been worked with and will be patched in the nearest future.

MeowyPouncer commented 1 year ago

All of the given sites' issues were resolved; wait for the patch.