OSINT tool to extract info about persons from git repositories: common names, emails, matches between different (as it may seems) accounts. Using Install git Run: repos by nickname ./gitcolombo.py --nickname LubyRuffy"> # from any git url
./gitcolombo.py -u https://github.com/Kalanchyovskaia16/newlps
# from directory, recursively
./gitcolombo.py -d ./newlps -r
# from all GitHub personal/org repos by nickname
./gitcolombo.py --nickname LubyRuffy
For batch (https://www.kitploit.com/search/label/Batch) cloning (https://www.kitploit.com/search/label/Cloning) from Gitlab and Bitbucket group repos you can use ghorg (https://github.com/gabrie30/ghorg).
Output: verbose persons info name email number of appearences as author/committer other persons that person can be emails used for the same name different names for the same person general statistics Details [RUS] https://telegra.ph/Gitcolombo---OSINT-v-GitHub-03-02 What's the difference between git author and committer? TL;DR author wrote the code (make the patch) commiter commit it to the repo (rewrite history, make pull/merge requests...) Nice explanation: https://stackoverflow.com/questions/18750808/difference-between-author-and-committer-in-git Very often developers make inaccurate commits with the one name/email (e.g. work account), then change to the right (e.g. personal account) and make git commit --amend, but forget to change the author of the commit. This way we can use it for OSINT (https://www.kitploit.com/search/label/OSINT) as match of names/emails from git history. TODO Total statistics for repos in a directory Check different names for every email GitHub support: clone all repos from account/group GitHub support: api pagination GitHub support: extract links to accounts from commit info Exclude "system" accounts (e.g. noreply@github.com (mailto:noreply@github.com)) Probabilistic graph (https://www.kitploit.com/search/label/Graph) links based on same names/emails and Levenshtein distance Other popular git platforms: Gitlab, Bitbucket and also
Download Gitcolombo (https://github.com/soxoj/gitcolombo)
___________________________
@hacking_Attack
@Hacking_Video
./gitcolombo.py -u https://github.com/Kalanchyovskaia16/newlps
# from directory, recursively
./gitcolombo.py -d ./newlps -r
# from all GitHub personal/org repos by nickname
./gitcolombo.py --nickname LubyRuffy
For batch (https://www.kitploit.com/search/label/Batch) cloning (https://www.kitploit.com/search/label/Cloning) from Gitlab and Bitbucket group repos you can use ghorg (https://github.com/gabrie30/ghorg).
Output: verbose persons info name email number of appearences as author/committer other persons that person can be emails used for the same name different names for the same person general statistics Details [RUS] https://telegra.ph/Gitcolombo---OSINT-v-GitHub-03-02 What's the difference between git author and committer? TL;DR author wrote the code (make the patch) commiter commit it to the repo (rewrite history, make pull/merge requests...) Nice explanation: https://stackoverflow.com/questions/18750808/difference-between-author-and-committer-in-git Very often developers make inaccurate commits with the one name/email (e.g. work account), then change to the right (e.g. personal account) and make git commit --amend, but forget to change the author of the commit. This way we can use it for OSINT (https://www.kitploit.com/search/label/OSINT) as match of names/emails from git history. TODO Total statistics for repos in a directory Check different names for every email GitHub support: clone all repos from account/group GitHub support: api pagination GitHub support: extract links to accounts from commit info Exclude "system" accounts (e.g. noreply@github.com (mailto:noreply@github.com)) Probabilistic graph (https://www.kitploit.com/search/label/Graph) links based on same names/emails and Levenshtein distance Other popular git platforms: Gitlab, Bitbucket and also
Download Gitcolombo (https://github.com/soxoj/gitcolombo)
___________________________
@hacking_Attack
@Hacking_Video
Use of Default Credentials to Unauthorised Remote Access of Internal Panel of Network Video…
👨🏼💻Discovered by Dnyanesh A. GawandeContinue reading on Medium »
Read more...
👨🏼💻Discovered by Dnyanesh A. GawandeContinue reading on Medium »
Read more...
Use of Default Credentials to Unauthorised Remote Access of Internal Panel of Network Video…
https://medium.com/@dnyanesh766/use-of-default-credentials-to-unauthorised-remote-access-of-internal-panel-of-network-video-5490d107fa0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@dnyanesh766/use-of-default-credentials-to-unauthorised-remote-access-of-internal-panel-of-network-video-5490d107fa0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Use of Default Credentials to Unauthorised Remote Access of Internal Panel of Network Video…
👨🏼💻Discovered by Dnyanesh A. Gawande
👨🏼💻Discovered by Dnyanesh A. GawandeContinue reading on Medium » (https://medium.com/@dnyanesh766/use-of-default-credentials-to-unauthorised-remote-access-of-internal-panel-of-network-video-5490d107fa0?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Use of Default Credentials to Unauthorised Remote Access of Internal Panel of Network Video…
👨🏼💻Discovered by Dnyanesh A. Gawande
Zenlink заключил партнерство с Immunefi и запустил программу по поиску ошибок
https://medium.com/@black322/zenlink-%D0%B7%D0%B0%D0%BA%D0%BB%D1%8E%D1%87%D0%B8%D0%BB-%D0%BF%D0%B0%D1%80%D1%82%D0%BD%D0%B5%D1%80%D1%81%D1%82%D0%B2%D0%BE-%D1%81-immunefi-%D0%B8-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D1%82%D0%B8%D0%BB-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D0%BC%D1%83-%D0%BF%D0%BE-%D0%BF%D0%BE%D0%B8%D1%81%D0%BA%D1%83-%D0%BE%D1%88%D0%B8%D0%B1%D0%BE%D0%BA-872674b0d84c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@black322/zenlink-%D0%B7%D0%B0%D0%BA%D0%BB%D1%8E%D1%87%D0%B8%D0%BB-%D0%BF%D0%B0%D1%80%D1%82%D0%BD%D0%B5%D1%80%D1%81%D1%82%D0%B2%D0%BE-%D1%81-immunefi-%D0%B8-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D1%82%D0%B8%D0%BB-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D0%BC%D1%83-%D0%BF%D0%BE-%D0%BF%D0%BE%D0%B8%D1%81%D0%BA%D1%83-%D0%BE%D1%88%D0%B8%D0%B1%D0%BE%D0%BA-872674b0d84c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Zenlink заключил партнерство с Immunefi и запустил программу по поиску ошибок
Сегодня 23 марта 2022 года , и мы рады сообщить, что компания Zenlink заключила партнерство с Immunefi и запустила программу по поиску…
Сегодня 23 марта 2022 года , и мы рады сообщить, что компания Zenlink заключила партнерство с Immunefi и запустила программу по поиску…Continue reading on Medium » (https://medium.com/@black322/zenlink-%D0%B7%D0%B0%D0%BA%D0%BB%D1%8E%D1%87%D0%B8%D0%BB-%D0%BF%D0%B0%D1%80%D1%82%D0%BD%D0%B5%D1%80%D1%81%D1%82%D0%B2%D0%BE-%D1%81-immunefi-%D0%B8-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D1%82%D0%B8%D0%BB-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D0%BC%D1%83-%D0%BF%D0%BE-%D0%BF%D0%BE%D0%B8%D1%81%D0%BA%D1%83-%D0%BE%D1%88%D0%B8%D0%B1%D0%BE%D0%BA-872674b0d84c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Zenlink заключил партнерство с Immunefi и запустил программу по поиску ошибок
Сегодня 23 марта 2022 года , и мы рады сообщить, что компания Zenlink заключила партнерство с Immunefi и запустила программу по поиску…
Zenlink уклав партнерство з Immunefi і запустив програму пошуку помилок
https://medium.com/@black322/zenlink-%D1%83%D0%BA%D0%BB%D0%B0%D0%B2-%D0%BF%D0%B0%D1%80%D1%82%D0%BD%D0%B5%D1%80%D1%81%D1%82%D0%B2%D0%BE-%D0%B7-immunefi-%D1%96-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D1%82%D0%B8%D0%B2-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D1%83-%D0%BF%D0%BE%D1%88%D1%83%D0%BA%D1%83-%D0%BF%D0%BE%D0%BC%D0%B8%D0%BB%D0%BE%D0%BA-8ac6c4af1416?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@black322/zenlink-%D1%83%D0%BA%D0%BB%D0%B0%D0%B2-%D0%BF%D0%B0%D1%80%D1%82%D0%BD%D0%B5%D1%80%D1%81%D1%82%D0%B2%D0%BE-%D0%B7-immunefi-%D1%96-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D1%82%D0%B8%D0%B2-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D1%83-%D0%BF%D0%BE%D1%88%D1%83%D0%BA%D1%83-%D0%BF%D0%BE%D0%BC%D0%B8%D0%BB%D0%BE%D0%BA-8ac6c4af1416?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Zenlink уклав партнерство з Immunefi і запустив програму пошуку помилок
Сьогодні 23 березня 2022 року, і ми раді повідомити, що компанія Zenlink уклала партнерство з Immunefi і запустила програму пошуку помилок.
Сьогодні 23 березня 2022 року, і ми раді повідомити, що компанія Zenlink уклала партнерство з Immunefi і запустила програму пошуку помилок.Continue reading on Medium » (https://medium.com/@black322/zenlink-%D1%83%D0%BA%D0%BB%D0%B0%D0%B2-%D0%BF%D0%B0%D1%80%D1%82%D0%BD%D0%B5%D1%80%D1%81%D1%82%D0%B2%D0%BE-%D0%B7-immunefi-%D1%96-%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D1%82%D0%B8%D0%B2-%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D1%83-%D0%BF%D0%BE%D1%88%D1%83%D0%BA%D1%83-%D0%BF%D0%BE%D0%BC%D0%B8%D0%BB%D0%BE%D0%BA-8ac6c4af1416?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Zenlink уклав партнерство з Immunefi і запустив програму пошуку помилок
Сьогодні 23 березня 2022 року, і ми раді повідомити, що компанія Zenlink уклала партнерство з Immunefi і запустила програму пошуку помилок.
Hacking on Medium
https://balochistanjob1.blogspot.com/2022/03/north-korean-hackers-stole-google.html
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
https://balochistanjob1.blogspot.com/2022/03/north-korean-hackers-stole-google.html
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
https://balochistanjob1.blogspot.com/2022/03/north-korean-hackers-stole-google.html
https://balochistanjob1.blogspot.com/2022/03/north-korean-hackers-stole-google.html
Hacking on Medium
End of the Road for the Teenagers at LAPSUS$
https://cdn-images-1.medium.com/max/714/1*OzwC0RvHXyCbTJ-Vn6hVFg.png
The teenagers, LAPSUS$, responsible for high-profile hacks at Samsung, NVidia and Microsoft have been arrested.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
End of the Road for the Teenagers at LAPSUS$
https://cdn-images-1.medium.com/max/714/1*OzwC0RvHXyCbTJ-Vn6hVFg.png
The teenagers, LAPSUS$, responsible for high-profile hacks at Samsung, NVidia and Microsoft have been arrested.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Dangerous Teenagers At Hack
The teenagers, LAPSUS$, responsible for high-profile hacks at Samsung, NVidia and Microsoft have been arrested.
Hacking on Medium
Scan Your Perimeter Before They Do…
https://cdn-images-1.medium.com/max/2048/1*7wLZ8V-XBV4MHzah7K0lhA.png
LAPSUS$ seems to be the new focus after their recent activity surrounding Microsoft and Okta. If you’ve not seen, here is Microsofts blog.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Scan Your Perimeter Before They Do…
https://cdn-images-1.medium.com/max/2048/1*7wLZ8V-XBV4MHzah7K0lhA.png
LAPSUS$ seems to be the new focus after their recent activity surrounding Microsoft and Okta. If you’ve not seen, here is Microsofts blog.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Scan Your Perimeter Before They Do…
LAPSUS$ seems to be the new focus after their recent activity surrounding Microsoft and Okta. If you’ve not seen, here is Microsofts blog.
Hacking on Medium
TryHackMe: [Day 4] Web Exploitation Santa’s Running Behind
https://cdn-images-1.medium.com/max/1920/1*psaTaSfd9sQyajFeYTLO-w.png
Access the login form at http://MACHINE_IP
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe: [Day 4] Web Exploitation Santa’s Running Behind
https://cdn-images-1.medium.com/max/1920/1*psaTaSfd9sQyajFeYTLO-w.png
Access the login form at http://MACHINE_IP
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe: [Day 4] Web Exploitation Santa’s Running Behind
Access the login form at http://MACHINE_IP
Hacking on Medium
Cracking SSH/RSA private keys
https://cdn-images-1.medium.com/max/2600/1*ZbMwDsyZbDVXeghW6kDLCQ.jpeg
One of the several ways to secure your SSH server is to disable password logins and enable login using an RSA private key, which may…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cracking SSH/RSA private keys
https://cdn-images-1.medium.com/max/2600/1*ZbMwDsyZbDVXeghW6kDLCQ.jpeg
One of the several ways to secure your SSH server is to disable password logins and enable login using an RSA private key, which may…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cracking SSH/RSA private keys
One of the several ways to secure your SSH server is to disable password logins and enable login using an RSA private key, which may…
Zenlink заключил партнерство с Immunefi и запустил программу по поиску ошибок
Сегодня 23 марта 2022 года , и мы рады сообщить, что компания Zenlink заключила партнерство с Immunefi и запустила программу по поиску…Continue reading on Medium »
Read more...
Сегодня 23 марта 2022 года , и мы рады сообщить, что компания Zenlink заключила партнерство с Immunefi и запустила программу по поиску…Continue reading on Medium »
Read more...
Zenlink уклав партнерство з Immunefi і запустив програму пошуку помилок
Сьогодні 23 березня 2022 року, і ми раді повідомити, що компанія Zenlink уклала партнерство з Immunefi і запустила програму пошуку помилок.Continue reading on Medium »
Read more...
Сьогодні 23 березня 2022 року, і ми раді повідомити, що компанія Zenlink уклала партнерство з Immunefi і запустила програму пошуку помилок.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Gitcolombo - Extract And Analyze Contributors Info From Git Repos
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivS4cm9RurhdCDvKKBDrGCxhKs7UJV6v9s5eIc1YQyq23ZZWtpy84sAIIbeQ3M5jCTqy4SUTeOQUNUMpH3FR1H7r2WMNvqdC-BZ4LpGL9SFuDQlSSv59NzGW12JtS1EO3qpKOJpaCrzgCYR9RSlHnz2w54tk6LIYk7UMX1LxI9JwiaFSMCmqMQeFd0/w640-h462/gitcolombo.png
OSINT tool to extract info about persons from git repositories: common names, emails, matches between different (as it may seems) accounts.
Using
1.
Install git
2.
Run:
repos by nickname ./gitcolombo.py --nickname LubyRuffy">
For batch cloning from Gitlab and Bitbucket group repos you can use ghorg.
Output:
*
verbose persons info
* name
* email
* number of appearences as author/committer
* other persons that person can be
*
emails used for the same name
*
different names for the same person
*
general statistics
Details
[RUS] https://telegra.ph/Gitcolombo---OSINT-v-GitHub-03-02
What's the difference between git author and committer?
TL;DR
* author wrote the code (make the patch)
* commiter commit it to the repo (rewrite history, make pull/merge requests...)
Nice explanation: https://stackoverflow.com/questions/18750808/difference-between-author-and-committer-in-git
Very often developers make inaccurate commits with the one name/email (e.g. work account), then change to the right (e.g. personal account) and make
TODO
* Total statistics for repos in a directory
* Check different names for every email
* GitHub support: clone all repos from account/group
* GitHub support: api pagination
* GitHub support: extract links to accounts from commit info
* Exclude "system" accounts (e.g. noreply@github.com)
* Probabilistic graph links based on same names/emails and Levenshtein distance
* Other popular git platforms: Gitlab, Bitbucket and also
Download Gitcolombo
___________________________
@hacking_Attack
@Hacking_Video
Gitcolombo - Extract And Analyze Contributors Info From Git Repos
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivS4cm9RurhdCDvKKBDrGCxhKs7UJV6v9s5eIc1YQyq23ZZWtpy84sAIIbeQ3M5jCTqy4SUTeOQUNUMpH3FR1H7r2WMNvqdC-BZ4LpGL9SFuDQlSSv59NzGW12JtS1EO3qpKOJpaCrzgCYR9RSlHnz2w54tk6LIYk7UMX1LxI9JwiaFSMCmqMQeFd0/w640-h462/gitcolombo.png
OSINT tool to extract info about persons from git repositories: common names, emails, matches between different (as it may seems) accounts.
Using
1.
Install git
2.
Run:
repos by nickname ./gitcolombo.py --nickname LubyRuffy">
# from any git url
./gitcolombo.py -u https://github.com/Kalanchyovskaia16/newlps
# from directory, recursively
./gitcolombo.py -d ./newlps -r
# from all GitHub personal/org repos by nickname
./gitcolombo.py --nickname LubyRuffy
For batch cloning from Gitlab and Bitbucket group repos you can use ghorg.
Output:
*
verbose persons info
* name
* number of appearences as author/committer
* other persons that person can be
*
emails used for the same name
*
different names for the same person
*
general statistics
Details
[RUS] https://telegra.ph/Gitcolombo---OSINT-v-GitHub-03-02
What's the difference between git author and committer?
TL;DR
* author wrote the code (make the patch)
* commiter commit it to the repo (rewrite history, make pull/merge requests...)
Nice explanation: https://stackoverflow.com/questions/18750808/difference-between-author-and-committer-in-git
Very often developers make inaccurate commits with the one name/email (e.g. work account), then change to the right (e.g. personal account) and make
git commit --amend, but forget to change the author of the commit. This way we can use it for OSINT as match of names/emails from git history.TODO
* Total statistics for repos in a directory
* Check different names for every email
* GitHub support: clone all repos from account/group
* GitHub support: api pagination
* GitHub support: extract links to accounts from commit info
* Exclude "system" accounts (e.g. noreply@github.com)
* Probabilistic graph links based on same names/emails and Levenshtein distance
* Other popular git platforms: Gitlab, Bitbucket and also
Download Gitcolombo
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Gitcolombo - Extract And Analyze Contributors Info From Git Repos