විවිධ Web Services සහ Platforms වල Register වීමට Email ලිපිනයන් භාවිතා කරමු. නමුත් එම Third-party Database එකක් Cyber Attack එකකට ලක්වුවහොත්, අපගේ Passwords සහ Personal Data, Dark Web එකට හෝ Public Breach Dumps වෙත Leak වීමේ ලොකු අවදානමක් පවතියි.
Reconnaissance සහ Threat Intelligence වලදී, යම් Email එකක් හෝ Domain එකක් past data breaches වලට අසුවී තිබේදැයි සොයා බැලීමට Security Researchers ලා සහ OSINT Analysts ලා බහුලව භාවිතා කරන Powerful Tool එකක් වන්නේ h8mail ය.
h8mail යනු කුමක්ද? එය ක්රියාත්මක වන්නේ කොහොමද?
h8mail යනු Python පදනම් කරගෙන නිර්මාණය කරන ලද Open-Source Email OSINT සහ Password Breach Hunting Tool එකකි. මෙය නිර්මාණය කරන ලද්දේ Security Researcher khast3x විසිනි.
h8mail මඟින් සිදු කරන්නේ:
Breach Data APIs Query කිරීම: HaveIBeenPwned, BreachDirectory, DeHashed, IntelX, Scylla වැනි ප්රකට OSINT Breach Data APIs හරහා අදාළ Email එකට සම්බන්ධ Leaked Data තිබේදැයි සෙවීම.
Local Leak Parsing: Local Hard Drive එකේ පවතින Text Dumps, Breach Compilation Files, CSV හෝ JSON raw files තුළින් Regex Pattern Matching හරහා ඉතා ඉක්මනින් Email සහ Plaintext/Hash Passwords Extract කරගැනීම.
Asynchronous Architecture: Async I/O (asyncio) භාවිතා කරන නිසා එකවර Multiple Emails සහ Multi-source APIs ඉතාම වේගයෙන් Scan කිරීමේ හැකියාව ඇත.
Practical Usage & CLI Commands
h8mail Tool එක Linux, Kali Linux, Windows හෝ macOS terminal හරහා පහසුවෙන් Install කර run කළ හැක.
1. Installation
Python 3 සහ pip3 ඔබේ system එකේ ස්ථාපනය වී තිබිය යුතුය.
“pip3 install h8mail”
මේකෙන් වෙන්නේ: Python Package Index (PyPI) හරහා h8mail හි නවතම version එක download වී install වීමයි.
(Verification: Installation එක සාර්ථකදැයි පරීක්ෂා කිරීමට terminal එකේ h8mail -h ලෙස type කර help menu එක පැමිණේදැයි බලන්න.)
2. Basic Single Target Scan
තනි Email ලිපිනයක් Public APIs හරහා Scan කිරීමට:
“h8mail -t [email protected]”
මේකෙන් වෙන්නේ: ලබාදුන් Email එකට අදාළව API Data Sources වල ඇති Breach Status එක terminal එකේ Display කිරීමයි.
3. Scanning Multiple Targets (Bulk Scan)
Email ලිපින එකකට වඩා පැවතියහොත්, ඒවා Text File එකක (targets.txt) ලියා bulk scan එකක් කළ හැක:
“h8mail -t targets.txt”
මේකෙන් වෙන්නේ: File එකේ ඇති සියලුම Email ලිපින sequentially හෝ asynchronously Scan කර Summary Report එකක් ලබාදීමයි.
4. API Keys භාවිතය (Generating Config File)
Breach APIs වල නොමිලේ ලබාදෙන Endpoints වල සීමාවන් (Rate Limits) පවතියි. DeHashed, IntelX හෝ Premium HIBP API Keys එකතු කිරීමට Config File එකක් සාදාගත යුතුය.
“h8mail -g”
මේකෙන් වෙන්නේ: h8mail_config.ini නමින් Default Configuration Template එකක් සාදාදීමයි.
ඉන්පසු එම file එක text editor එකකින් open කර ඔබේ API Keys ඇතුළත් කර, පහත ලෙස command එක ලබාදිය හැක:
“h8mail -t targets.txt -c h8mail_config.ini”
5. Local Breach File Scanning
ඔබ සතුව Local Breach Dumps (උදා: BreachCompilation raw text files) පවතී නම්, APIs භාවිතා නොකර Local Files වලින් Data Parse කිරීමට:
“h8mail -t targets.txt -b /path/to/local_breach_file.txt”
මේකෙන් වෙන්නේ: Local File එක තුළ ඇති Email:Password combinations Regex මඟින් Match කර පෙන්වීමයි.
Advanced Insights
Custom Regex Matching: Local files scan කිරීමේදී loose හෝ strict regex patterns (-bc options) යොදාගනිමින් Custom Text formats ඇතුළෙන් අවශ්ය Email/Password hashes පමණක් isolative ලෙස extract කරගැනීමට h8mail සමත් වේ.
OPSEC Advantage: Default Public Search Engines හරහා Manual සෙවීම් සිදුකිරීමට වඩා, Configured API Endpoints හරහා Query කිරීමෙන් Target එක දැනුවත් නොවී Clean Intelligence Report එකක් ලබාගත හැක.
JSON/CSV Exporting: Red Team Engagement එකකදී හෝ Defensive Audit එකකදී ලබාගන්නා Findings, -o output.json මඟින් Structured Output format එකකට Export කරගත හැක.
Attack vs Defense Perspective
Attacker / Red Team Perspective
Attackers ලා Initial Reconnaissance (Phishing / Social Engineering) අදියරේදී Organization එකක Employees ලගේ Leaked Passwords සොයාගැනීමට h8mail යොදාගනී.
Credential Stuffing & Password Spraying: කලින් Breach වුණු Passwords, වෙනත් Corporate Systems වල Re-use කර තිබේදැයි බලයි.
Defender / Blue Team / SOC Perspective
Domain Breach Exposure Monitoring: Security Analysts ලා තමන්ගේ Organization එකේ Domain එකට (උදා: @company.com) අදාළ Emails leak වී තිබේදැයි නිරන්තරයෙන් Audit කිරීමට භාවිතා කරයි.
Proactive Password Reset Mandates ක්රියාත්මක කිරීමටත්, Vulnerable Users ලා හඳුනාගෙන Multi-Factor Authentication (MFA) Enforce කිරීමටත් මෙය උපකාරී වේ.
Common Misconceptions
මිත්යාව: “h8mail කියන්නේ ඕනෑම Email එකක Password එක එක ක්ලික් එකෙන් Hack කරන්න පුළුවන් Tool එකක්.”
සත්යය: h8mail යනු Hacking tool එකක් නොවේ. මෙය අතීතයේ සිදුවූ Data Breaches (Past Data) වල සටහන් වූ Publicly / Darkweb Leaked Data එකතු කර පෙන්වන OSINT Assessment Tool එකක් පමණි.
LEGAL / ETHICAL WARNING
මේ Techniques සහ Tools තමන්ගේම Lab Environment එකක, Audit කිරීමට Explicit Authorization සහ Permission ඇති Domain/Emails සඳහා පමණක් භාවිතා කරන්න.
අවසරයකින් තොරව වෙනත් පුද්ගලයෙකුගේ හෝ ආයතනයක Credentials, Data Breaches හරහා Search කර අනිසි ලෙස භාවිතා කිරීම සහ Targeted Reconnaissance සිදුකිරීම නීතිවිරෝධී වේ.
Conclusion
h8mail යනු OSINT Researchers ලාට සහ Cyber Security Defenders ලාට Target Credentials වල Risk Level එක සහ Past Exposure එක තත්පර ගණනකින් Analyze කරගැනීමට ලැබෙන ඉතාම කාර්යක්ෂම Terminal Tool එකකි. Password Re-use වැළැක්වීම සහ MFA භාවිතය මෙවැනි Leaked Data වලින් සිදුවන හානි අවම කරගැනීමට ඇති හොඳම විසඳුමයි.
Fsociety.LK
