Credmap is an open source credential mapper tool that was created to bring awareness to the dangers of credential reuse. It is capable of testing supplied user credentials on several known websites to test if the password has been reused on any of these.
It is not uncommon for people who are not experts in security to reuse credentials on different websites; even security savvy people occasionally reuse credentials.
Credmap takes a username and/or e-mail, and a password as input and it attempts to login on a variety of known websites to verify if these credentials have been reused on any of them.
-h/–help show this help message and exit
-v/–verbose display extra output information
-u/–username=USER.. set the username to test with
-p/–password=PASS.. set the password to test with
-e/–email=EMAIL set an email to test with
-l/–load=LOAD_FILE load list of credentials in format USER:PASSWORD
-f/–format=CRED_F.. format to use when reading from file (e.g. u|e:p)
-x/–exclude=EXCLUDE exclude sites from testing
-o/–only=ONLY test only listed sites
-s/–safe-urls only test sites that use HTTPS.
-i/–ignore-proxy ignore system default HTTP proxy
–proxy=PROXY set proxy (e.g. “socks5://192.168.1.2:9050”)
–list list available sites to test with
Usage: credmap.py —email EMAIL | —user USER | —load LIST [options]
–h/—help show this help message and exit
–v/—verbose display extra output information
–u/—username=USER.. set the username to test with
–p/—password=PASS.. set the password to test with
–e/—email=EMAIL set an email to test with
–l/—load=LOAD_FILE load list of credentials in format USER:PASSWORD
–f/—format=CRED_F.. format to use when reading from file (e.g. u|e:p)
–x/—exclude=EXCLUDE exclude sites from testing
–o/—only=ONLY test only listed sites
–s/—safe–urls only test sites that use HTTPS.
–i/—ignore–proxy ignore system default HTTP proxy
—proxy=PROXY set proxy (e.g. “socks5://192.168.1.2:9050”)
—list list available sites to test with
./credmap.py —username janedoe —email email@example.com
./credmap.py –u johndoe –e firstname.lastname@example.org —exclude “github.com, live.com”
./credmap.py –u johndoe –p abc123 –vvv —only “linkedin.com, facebook.com”
./credmap.py –e email@example.com —verbose —proxy “https://127.0.0.1:8080”
./credmap.py —load creds.txt —format “e.u.p”
./credmap.py –l creds.txt –f “u|e:p”
./credmap.py –l creds.txt
You can download credmap here:
Or read more here.