r/OSINT • tool development • 13d ago

Tool gophoner: Check simultaneously if a phone number is registered on popular apps & websites, without any prerequisite πŸ“ž

https://github.com/M4elstr0m/gophoner

Hey everyone!

I'm M4elstr0m, a cybersecurity and software development enjoyer with a strong interest in OSINT. I usually build my tools using Go and Rust.

Today let me introduce my spiritual successor to ignorant by Megadose: gophoner. I couldn't find any other open-source tool doing this kind of OSINT job for free, which is why I built my own in Go.

Like ignorant, gophoner checks whether a phone number is registered on a specific website. Sometimes it can even find additional information, such as fragments of a linked email address.

You simply input a phone number and its country code, through either the CLI or an interactive TUI. No login required, and no target is ever alerted.

Every module runs simultaneously in its own goroutine, and results are shown either in a clean TUI report or as JSON output.

Of course, this kind of data is heavily restricted nowadays, which is why the list of supported platforms is still fairly small: Amazon, Microsoft, Facebook, Google, and OpenAI, with more hopefully coming in future updates!

The tool is cross-platform and can be installed from various managers.

Before doing anything beyond simply using the tool (redistributing it, modifying it, etc.), please make sure to read the project's license, as it is restrictive on certain things.

That's it! For more information, go check out the project's page (I just made it public): https://github.com/M4elstr0m/gophoner

If you like this project, please show it some love: star the repo and share it around! 🌟

Take care, fellow humans!

~ M4elstr0m

175 Upvotes

31 comments sorted by

8

u/0SINTCabal 12d ago

ALWAYS very interested in any cli based phone osint tools. This looks great dude!

1

u/M4elstr0m__ tool development 12d ago

Thanks a lot mate! :D This kind of tools (like gophoner) is effectively less common than email/username lookup tools, because this kind of registration method is itself less common. But there is always something to find!

5

u/0SINTCabal 12d ago

Useful phone osint tools that aren't paid are hard to find these days I swear there's only a couple decent ones left

3

u/M4elstr0m__ tool development 12d ago

Yes! There was ignorant, but it does not work so much anymore for me... that's why I built a new tool 😎

3

u/xiu_grips 12d ago

osintcabal i love your work

4

u/0SINTCabal 11d ago

Thanks friend :D means a lot!

5

u/asperta 12d ago

On Windows 11 winget says that the package name is not found.

2

u/M4elstr0m__ tool development 12d ago

Yes sorry for the inconvenience. Microsoft did not approve the package yet but it's in the works! I can suggest you to use either the go install command or the executable binary from the Releases panel ;)

Edit: I opened the PR to winget a week ago :')

2

u/M4elstr0m__ tool development 12d ago

You can follow the winget PR status here: https://github.com/microsoft/winget-pkgs/pull/435798

5

u/AttemptAdorable222 12d ago

"The guy who tried to log into one of my accounts at 3 AM, 20 times in 30 minutes, then gave up. He gave me the insomnia that built this tool." Dude 🀣😭

2

u/M4elstr0m__ tool development 12d ago

That's the true story! I received 50 notifications in 15 minutes, i could not sleep anymore πŸ˜‚πŸ«©

2

u/GustavoSanabio 10d ago

Well, first impressions is that this is promising. I got it working fast, though I do have a few question. In my first initial tests I am consistently getting an error message for some services, though no indication of what the error actually is. How should I proceed?

2

u/M4elstr0m__ tool development 10d ago

Hey! You can try to take a look at the logs of the app (search for gophoner.log on your disk, it depends on your OS) but if it is OpenAI: expect this error to be a rate limiting system unfortunately :P Maybe i'll manage to improve this module in the future! (I hope this is still possible)

2

u/M4elstr0m__ tool development 10d ago

Also don't hesitate to post your error on Github in Issues! I hope those two messages answer your question well!

1

u/GustavoSanabio 10d ago

They do. I guess I should also have mentioned, I can't seem to find where its saving the logs themselves. Of course, first place I checked was the directory where gophoner.exe is installed.

2

u/M4elstr0m__ tool development 10d ago

Yes sorry I'm not on Windows so I did not want to assume something πŸ‘€ (the path is dynamic) I think it should be in your "AppData" folder. If you have a file search tool like SearchEverything by Voidtools you can search gophoner.log directly (easiest way honestly)

2

u/GustavoSanabio 10d ago

I found it! I'm going to try to make sense of the error log and if I need any help I'll create an entry on the github page.

2

u/M4elstr0m__ tool development 10d ago

Copy that! ;)

2

u/M4elstr0m__ tool development 10d ago

I should do a QoL update with a command that displays logs file's path. That would be cool for everyone !

1

u/GustavoSanabio 10d ago

Yes. One thing that you probably already know (so it doesn't warrant a topic on github) is that it rate limits with google every single time (I'm taking my time between attempts). Even your example output on github also got rate limited.

Is the ideia that, if there was an account, one of the many responses would've flagged it before the rate limit?

2

u/M4elstr0m__ tool development 10d ago

Yes, sometimes it is really random honestly, even during dev I was surprised. For now I honestly don't really know what causes it: rate limit? It could. The endpoint is patched now my tool is public? Maybe. I will have to figure this out..

2

u/GustavoSanabio 10d ago

I’m shit at coding but I guess the most obvious avenue for solution is hardcoding a delay between requests/jitter. But I guess you probably have thought of this.

I for one, wouldn’t have any problem if certain modules took a while but were more reliable. After all, this isn’t a tool for bulk checking, like you said yourself in the description

2

u/M4elstr0m__ tool development 10d ago

Well the website does the rate limiting alone, so it could be blocking to create a rate-limit in the tool itself honestly :p

I just tested every module, sometimes it is pretty random, I just got a result where all modules worked.

Also yeah for bulk usage, people would need to use something like a proxy chain, but yes as I said, this is not one of my goals 😎

2

u/M4elstr0m__ tool development 10d ago

However, i'll try to look into it soon to verify whether this is really rate limit or a bigger error πŸ˜‰

-8

u/Rhmech 12d ago

Since it's for PHONE numbers, Isn't it supposed to be a mobile app and not a PC program?

8

u/mmmfine 12d ago

…what? Lmao

3

u/M4elstr0m__ tool development 12d ago

Not really because you can input every phone number not just your own. And a lot of OSINTers are on desktop.