mirror of
https://github.com/anotherhadi/github-recon.git
synced 2026-10-05 10:58:25 +02:00
@@ -20,6 +20,7 @@
|
|||||||
- [With Nix/NixOS](#with-nixnixos)
|
- [With Nix/NixOS](#with-nixnixos)
|
||||||
- [🧪 Usage](#-usage)
|
- [🧪 Usage](#-usage)
|
||||||
- [Flags](#flags)
|
- [Flags](#flags)
|
||||||
|
- [Token](#token)
|
||||||
- [💡 Examples](#-examples)
|
- [💡 Examples](#-examples)
|
||||||
- [🕵️♂️ Cover your tracks](#-cover-your-tracks)
|
- [🕵️♂️ Cover your tracks](#-cover-your-tracks)
|
||||||
- [🤝 Contributing](#-contributing)
|
- [🤝 Contributing](#-contributing)
|
||||||
@@ -38,20 +39,21 @@ other GitHub accounts, and more.
|
|||||||
**From usernames:**
|
**From usernames:**
|
||||||
|
|
||||||
- Retrieve basic user profile information (username, ID, avatar, bio, creation
|
- Retrieve basic user profile information (username, ID, avatar, bio, creation
|
||||||
dates)
|
date)
|
||||||
- Display the avatar in the terminal
|
- Display avatars directly in the terminal
|
||||||
- List organizations and roles
|
- List organizations and roles
|
||||||
- Fetch SSH and GPG keys
|
- Fetch SSH and GPG keys
|
||||||
- Enumerate social accounts
|
- Enumerate social accounts
|
||||||
- Extract unique commit authors (name + email)
|
- Extract unique commit authors (name + email)
|
||||||
- Find close friends
|
- Find close friends
|
||||||
- Deep scan option (clone repositories, regex search, analyze licenses, etc.)
|
- Deep scan option (clone repositories, run regex searches, analyze licenses,
|
||||||
- Levenshtein distance for matching usernames and emails
|
etc.)
|
||||||
|
- Use Levenshtein distance for matching usernames and emails
|
||||||
|
|
||||||
**From emails:**
|
**From emails:**
|
||||||
|
|
||||||
- Search for a specific email through all Github commits
|
- Search for a specific email across all GitHub commits
|
||||||
- Spoof an email to found an user account
|
- Spoof an email to discover the associated user account
|
||||||
|
|
||||||
## ⚠️ Disclaimer
|
## ⚠️ Disclaimer
|
||||||
|
|
||||||
@@ -116,6 +118,35 @@ github-recon [--flags value] target_username_or_email
|
|||||||
-j, --json string Write results to specified JSON file
|
-j, --json string Write results to specified JSON file
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Token
|
||||||
|
|
||||||
|
For the best experience, provide a **GitHub Personal Access Token**. Without a
|
||||||
|
token, you will quickly hit the **rate limit** and have to wait.
|
||||||
|
|
||||||
|
- For **basic usage**, you can create a token **without any permissions**.
|
||||||
|
- For the **email spoofing feature**, you need to add the **`repo`** and
|
||||||
|
**`delete_repo`** permissions.
|
||||||
|
|
||||||
|
You can set the token in multiple ways:
|
||||||
|
|
||||||
|
- **Command-line flag**:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
github-recon -t "ghp_xxx..."
|
||||||
|
```
|
||||||
|
|
||||||
|
- **Environment variable**:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
export GITHUB_RECON_TOKEN=ghp_xxx...
|
||||||
|
```
|
||||||
|
|
||||||
|
- **Config file**: Create the file `~/.config/github-recon/env` and add:
|
||||||
|
|
||||||
|
```env
|
||||||
|
GITHUB_RECON_TOKEN=ghp_xxx...
|
||||||
|
```
|
||||||
|
|
||||||
## 💡 Examples
|
## 💡 Examples
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
|
|||||||
Reference in New Issue
Block a user