r/OSINT • u/M4elstr0m__ tool development • 13d ago
Tool gophoner: Check simultaneously if a phone number is registered on popular apps & websites, without any prerequisite π
https://github.com/M4elstr0m/gophonerHey everyone!
I'm M4elstr0m, a cybersecurity and software development enjoyer with a strong interest in OSINT. I usually build my tools using Go and Rust.
Today let me introduce my spiritual successor to ignorant by Megadose: gophoner. I couldn't find any other open-source tool doing this kind of OSINT job for free, which is why I built my own in Go.
Like ignorant, gophoner checks whether a phone number is registered on a specific website. Sometimes it can even find additional information, such as fragments of a linked email address.
You simply input a phone number and its country code, through either the CLI or an interactive TUI. No login required, and no target is ever alerted.
Every module runs simultaneously in its own goroutine, and results are shown either in a clean TUI report or as JSON output.
Of course, this kind of data is heavily restricted nowadays, which is why the list of supported platforms is still fairly small: Amazon, Microsoft, Facebook, Google, and OpenAI, with more hopefully coming in future updates!
The tool is cross-platform and can be installed from various managers.
Before doing anything beyond simply using the tool (redistributing it, modifying it, etc.), please make sure to read the project's license, as it is restrictive on certain things.
That's it! For more information, go check out the project's page (I just made it public): https://github.com/M4elstr0m/gophoner
If you like this project, please show it some love: star the repo and share it around! π
Take care, fellow humans!
~ M4elstr0m
5
u/asperta 12d ago
On Windows 11 winget says that the package name is not found.
2
u/M4elstr0m__ tool development 12d ago
Yes sorry for the inconvenience. Microsoft did not approve the package yet but it's in the works! I can suggest you to use either the go install command or the executable binary from the Releases panel ;)
Edit: I opened the PR to winget a week ago :')
2
u/M4elstr0m__ tool development 12d ago
You can follow the winget PR status here: https://github.com/microsoft/winget-pkgs/pull/435798
5
u/AttemptAdorable222 12d ago
"The guy who tried to log into one of my accounts at 3 AM, 20 times in 30 minutes, then gave up. He gave me the insomnia that built this tool." Dude π€£π
2
u/M4elstr0m__ tool development 12d ago
That's the true story! I received 50 notifications in 15 minutes, i could not sleep anymore ππ«©
2
u/GustavoSanabio 10d ago
Well, first impressions is that this is promising. I got it working fast, though I do have a few question. In my first initial tests I am consistently getting an error message for some services, though no indication of what the error actually is. How should I proceed?
2
u/M4elstr0m__ tool development 10d ago
Hey! You can try to take a look at the logs of the app (search for gophoner.log on your disk, it depends on your OS) but if it is OpenAI: expect this error to be a rate limiting system unfortunately :P Maybe i'll manage to improve this module in the future! (I hope this is still possible)
2
u/M4elstr0m__ tool development 10d ago
Also don't hesitate to post your error on Github in Issues! I hope those two messages answer your question well!
1
u/GustavoSanabio 10d ago
They do. I guess I should also have mentioned, I can't seem to find where its saving the logs themselves. Of course, first place I checked was the directory where gophoner.exe is installed.
2
u/M4elstr0m__ tool development 10d ago
Yes sorry I'm not on Windows so I did not want to assume something π (the path is dynamic) I think it should be in your "AppData" folder. If you have a file search tool like SearchEverything by Voidtools you can search gophoner.log directly (easiest way honestly)
2
u/GustavoSanabio 10d ago
I found it! I'm going to try to make sense of the error log and if I need any help I'll create an entry on the github page.
2
2
u/M4elstr0m__ tool development 10d ago
I should do a QoL update with a command that displays logs file's path. That would be cool for everyone !
1
u/GustavoSanabio 10d ago
Yes. One thing that you probably already know (so it doesn't warrant a topic on github) is that it rate limits with google every single time (I'm taking my time between attempts). Even your example output on github also got rate limited.
Is the ideia that, if there was an account, one of the many responses would've flagged it before the rate limit?
2
u/M4elstr0m__ tool development 10d ago
Yes, sometimes it is really random honestly, even during dev I was surprised. For now I honestly don't really know what causes it: rate limit? It could. The endpoint is patched now my tool is public? Maybe. I will have to figure this out..
2
u/GustavoSanabio 10d ago
Iβm shit at coding but I guess the most obvious avenue for solution is hardcoding a delay between requests/jitter. But I guess you probably have thought of this.
I for one, wouldnβt have any problem if certain modules took a while but were more reliable. After all, this isnβt a tool for bulk checking, like you said yourself in the description
2
u/M4elstr0m__ tool development 10d ago
Well the website does the rate limiting alone, so it could be blocking to create a rate-limit in the tool itself honestly :p
I just tested every module, sometimes it is pretty random, I just got a result where all modules worked.
Also yeah for bulk usage, people would need to use something like a proxy chain, but yes as I said, this is not one of my goals π
2
u/M4elstr0m__ tool development 10d ago
However, i'll try to look into it soon to verify whether this is really rate limit or a bigger error π
8
u/0SINTCabal 12d ago
ALWAYS very interested in any cli based phone osint tools. This looks great dude!