diff --git a/README.md b/README.md index 790d3e1..1dbfadd 100755 --- a/README.md +++ b/README.md @@ -2,11 +2,6 @@
-
-
-
Twitter
-
@@ -20,15 +15,34 @@
| [BlackArch Linux](https://blackarch.org/) | [SecBSD](https://secbsd.org/) | [Tsurugi Linux](https://tsurugi-linux.org/) |
|  |  |  |
-pwnedOrNot uses [**haveibeenpwned**](https://haveibeenpwned.com/API/v3) v3 api to test email accounts and tries to find the **password** in **Pastebin Dumps**.
+---
-## Featured
-OSINT Collection Tools for Pastebin - Jake Creps
+pwnedOrNot works in two phases. In the **first** phase it tests the given email address using [**`HaveIBeenPwned v3 API`**](https://haveibeenpwned.com/API/v3) to find if the account have been breached in the past and in the **second** phase it searches the **password** in available **public dumps**.
-## [**Changelog**](https://github.com/thewhiteh4t/pwnedOrNot/wiki/Changelog)
+**`An API Key is required to use the tool. You can purchase a key from HIBP website linked below`**
+
+https://haveibeenpwned.com/API/v3
+
+---
+
+## Featured
+
+**> OSINT Collection Tools for Pastebin - Jake Creps**
+
+**> eForensics Magazine May 2020**
+
+---
+
+## Changelog
+
+https://github.com/thewhiteh4t/pwnedOrNot/wiki/Changelog
+
+---
## Features
-[**haveibeenpwned**](https://haveibeenpwned.com/API/v3) offers a lot of information about the compromised email, some useful information is displayed by this script:
+
+[**haveibeenpwned**](https://haveibeenpwned.com/API/v3) offers a lot of information about the compromised email, pwnedOrNot displays most useful information such as :
+
* Name of Breach
* Domain Name
* Date of Breach
@@ -37,7 +51,15 @@ pwnedOrNot uses [**haveibeenpwned**](https://haveibeenpwned.com/API/v3) v3 api t
* Retirement status
* Spam Status
-And with all this information **pwnedOrNot** can easily find passwords for compromised emails if the dump is accessible and it contains the password
+### About Passwords
+
+The chances of finding passwords depends upon the following factors :
+
+* If public dumps are available for the email address
+* If the public dumps are accessible
+ * Sometimes the dumps are removed
+* If the public dump contains password
+ * Sometimes a dump contains only email addresses
#### Tested on
* **Kali Linux**
@@ -45,13 +67,16 @@ And with all this information **pwnedOrNot** can easily find passwords for compr
* **Kali Nethunter**
* **Termux**
+> Windows users are suggested to use Kali Linux WSL2 or a VM
+
## Installation
**Ubuntu / Kali Linux / Nethunter / Termux**
```bash
git clone https://github.com/thewhiteh4t/pwnedOrNot.git
cd pwnedOrNot
-pip3 install requests
+chmod +x install.sh
+./install.sh
```
**BlackArch Linux**
@@ -123,5 +148,5 @@ python3 pwnedornot.py -c