Hunting Breached Credentials

 

  1. DeHashed
  2. breach-parse on github by hmaverickadams
./breach-parse.sh @tesla.com tesla.txt

cat tesla-master.txt

 

Scope!! Only US emails are in scope.

email format (f.last@tesla.com or first.last@tesla.com or flast@tesla.com)

Password patterns or password reuse

 

copy the list and paste it into the Ethical Hacking excel, sheet for breached accounts. Sometimes it auto delims for you. If not, check the video

 

If you’re stuck not getting access from breached passwords:

Keep taking information gathered from DeHashed and trying to find more credentials. For example, if you find an email and user, search for the user, then name if it’s unique enough, then new email and its passwords, then hashes of passwords

 

Also try this format: Seasonyear!

  • Winter2024
  • Winter2024!
  • Winter24
  • Winter24!

Reader ratings (none yet)

Ratings come from verified buyers only.