-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathBreached DB search.txt
More file actions
29 lines (19 loc) · 1.32 KB
/
Copy pathBreached DB search.txt
File metadata and controls
29 lines (19 loc) · 1.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
1. Have I Been Pawned?
Major social media and tech giants have suffered data breaches in the past. As a result, the leaked data is publicly available and, most of the
time contains PII like usernames, email addresses, mobile numbers and even passwords. Users may use the same password across all the websites; that
enables bad actors to re-use the same password against a user on a different platform for a complete account takeover. Many web services offer to
check if your email address or phone number is in a leaked database; HaveIBeenPwned is one of the free services.
URL : https://haveibeenpwned.com/
DB can be Searched for -
Usernames
Email Addresses
Mobile Numbers
Passwords
2. DeHashed
Similar website to HaveIBeenPawned.
URL : https://www.dehashed.com/
------------------------------------------------------------------------------------------------------------------------------------------------
These tools can discover information like -
A. Users who ask questions on public forums such as Stack Overflow but disclose sensitive information such as their credentials in the question.
B. Developers that upload scripts to services such as Github with credentials hardcoded.
C. Credentials being disclosed in past breaches since employees used their work accounts to sign up for other external websites.