How Hackers Find Anyone's Info From Just Their Instagram...
Watch this. I'm going to take this
Instagram handle, just one username, and
I'll get her real name, the city she
lives in, her phone number, and every
other account she's ever made online. I
got all of this through OSINT, open
source intelligence. Basically, all the
public information that's out there
about you online, scattered across the
internet. And I'm going to be showing
you exactly how it's done. But before we
go any further, everything I'm about to
show you on this video is done on my own
accounts. Don't do this with malicious
intent. OSINT by itself is legal, but
the second you start using it to stalk,
harass, or even scam someone, that's
where you cross the line and it becomes
illegal. Let's begin. The first tool I
want to show you guys here is called
OSINTGram, and it's pretty popular. It
has 12,000 stars on GitHub, and it does
one thing very well. You give it one
single Instagram username, and it pulls
back everything Instagram is publicly
leaking on that account. Without wasting
much time, let's just scroll down and
begin with the installation. And we can
either just clone this right here and
paste it in our terminal, or we can go
up here and click the big green button
and copy the web URL, then go to our
terminal and just type git clone, and
then paste in the web URL we just
copied. And while this is cloning,
scroll down and hit the subscribe
button. I would really appreciate it.
Once done, we CD into the tool, CDO, and
then tab to fill it out by itself. Press
enter. Let's list the Let's clear this
up first and then list the files. And
here inside the tool, we can see a bunch
of files and folders, and one of them is
requirements.txt.
This means we have a bunch of
dependencies to install so this tool can
run smoothly without any errors. And
also in the installation guide right
here, we see we first need to make a
virtual environment to install the
dependencies. So we copy this and we
just paste it in our terminal. Hit
enter. Now we load the virtual
environment that we just created. And to
do that, we go to the installation page
again, and in the fourth section, load
the virtual environment. If you're on
Windows, you use this command right
here, but since I'm on Kali Linux, I use
a source to activate it. I'll copy this
section, then paste it in my terminal.
Right click, paste to clipboard. And by
this part right here, you know it loaded
successfully. Now all that's left to do
is going to the dependencies. To to the
requirements of Instasheck. To do that,
we just copy right pip install -r
requirements.txt. We copy it, paste on
terminal, standard, and it takes a bit
to install. After it's done, we clean up
the terminal so it's nice and clean. And
now we're almost done, but there's one
more thing. We need to pull the data
somehow from Instagram. And then the
sixth step, right over here, open the
credentials.ini file in the config
folder. Let's go ahead and do that real
quick. There's the files, we can click
that inside config, list the files
again, and here we see it,
credentials.ini. Nano credentials and we
tab. Inside we have three fields,
username, password, and hiker_api_token.
There's two ways we can pull the data.
Either we log in into our normal
Instagram account using our username and
password, or use the hiker API token. In
my opinion, using your own Instagram
account is a very bad idea because
Instagram is very aggressive and cracks
down on bots. And as soon as the tool
starts pulling data, the Instagram is
going to think this account is a bot,
either going to lock it or ban it
completely. So, we should go with the
hiker API token. We get the token or the
access key that we need directly from
the website, and it says in the
paragraph right here, use hiker API
token from the website. Right click,
open new tab. First 100 requests are
free after registration and confirmation
with your Telegram. Let me show you.
When you go to the site, you get
redirected to the tokens page. And I
already did it and I'm all logged in,
and here's my access key, my token that
I need. Don't try to use it, it's going
to be deleted after this video. But once
you're here, scroll down, go to the
Telegram page, and just verify with the
bot, do /start. Once you're verified,
come here and you're going to have your
access key here. And in your terminal,
just go ahead and paste in your token
you just got, and then save it and exit.
Let's just clear the whole thing up, and
now we're set up and ready to go. And
for the last step, all we have to do is
just run the main file, main.py. So,
python3 main.py and target username, the
Instagram username of the target, to
spawn interactive prompt. Let's go ahead
and do that. So, python3
main.
py and the target username, the
Instagram account that I definitely
didn't made up. It's not one of my
alternate account named miss.firewall.
Yeah, when I made this account I thought
the username would be pretty funny. Now
it's just kind of cringe. I can't lie.
But let's just send it.
Uh it's in config folder. Let's just
exit it.
And then clear it again and let's run it
again. python3 main.py
miss
firewall
After it ran, we can see right here it
connected to the Highker API first and
then it found the target miss firewall
and then her Instagram ID.
Scrolling down, we first have to type
list to show all the commands we can
run. So let's just do that. list
And you can see a bunch of commands
starting from address, get all
registered address by the target photos,
clear cache with the tool, a bunch of
stuff. But first, let's just run info to
get basic information on the target.
info
And here we have some information again,
basic ones like the ID of the Instagram,
full name miss firewall, her bio hello,
my name is miss firewall. Miss fire I
must have misspelled it. And this is my
personal blog.
Followers zero, he has four followers,
two photos, two photos posted, business
account. It is a business account since
it is a personal blog.
Verified account false and here we have
her HD profile picture, a full HD
profile picture of uh
her profile.
And here we have it, her profile
picture. It's a um girl with a firewall
face.
Anyways, let's just move on to the next
one.
Let's do something like address. Get all
registered addresses by the target
photos. addrs And here, woohoo, we found
one addresses. One post with an address
and the address right here.
But she probably didn't give her full
address on the post. And we can see
right here, let me go out to the to the
profile. Instagram miss.firewall I'm
already logged in so I can show you
guys. And here we have the post and in
the location it says Anthony, Texas.
But why does it say a full address in
our terminal?
What most people don't know that
these these locations right here users
create them. Normal users like you and
me.
And then when they create them, they
first have to drop a pin on an exact
location. Then they can name that
location whatever like Anthony, Texas.
When a user goes to create a post,
Instagram suggests the closest pin near
that person.
It might say Anthony, Texas, but behind
that is an exact location, exact
address, a pin. So when the user was
choosing a location and saw Anthony,
Texas, she was like, "Yeah, that's where
I'm at the right now. I'm going to
choose it." Without knowing that in the
background, she actually doxxed herself
and gave out her full location. And then
we can go ahead and actually copy this
location and then go to our Google Maps
so I can show you. google.com/maps
and then we go ahead and paste in our
location we just copied.
And then we see the pin right here.
This address is showing to this location
right here, RV Jones Colina.
And when we go back to Instagram page,
here we see a sign, "Welcome to Texas."
Let us search up for that sign to see
exactly where it is.
Our address that we extracted is right
here. Let's go look up for the sign,
"Welcome to Texas" sign.
Our pin is right here and the "Welcome
to Texas" sign is right here. So she
took her picture here, then went on
Instagram to post it, searched up for a
location, Instagram saw the nearest pin
to her was named Anthony, Texas,
suggested it to her. She thought, "Yeah,
that's where I'm at, Anthony, Texas. I'm
going to choose it." Without thinking
much, but in the background, she
actually doxxed herself. Now let's try
something else. Let's try something like
following email. She doesn't have
followers, let's try following email.
This gets all the emails of users
followed by the target.
Let's copy that
and then paste it right in. And here we
got a three out of four emails from her
following list from Hack The Box,
Network Chuck, and David Bombal. These
were the first people that came to mind
when I first made the account, but
that's beside the point. What we got
here is super important during an
information gathering because now we
have leverage. We have something we can
pivot to when we hit a roadblock or a
wall. Now, we can always send nice
personalized
emails or DMs pretending to be Miss
Firewall to our friends. Let's imagine
these are our friends.
And now we can do for example hash tags
and get some hashtags on her posts. For
example, farm girl, family, Texas, road
trips. So, now we know she likes road
trips, she's a farm girl, she lives in
Anthony, Texas, and we can make nice
personalized DMs or emails to her
friends pretending to be her so we can
get her even more information on her.
Now, since we mapped out where she's
been, her friends, her hobbies, the most
obvious thing would be to look for
different accounts so we can extract
more information. And the tool for that
is Sherlock. I've already covered it in
one of my other OSINT videos, but I'm
going to cover it again.
And what it does is it that simple. You
give it a single username and it looks
through over 400 websites to check if
that username exists. You can also give
it multiple usernames, you can specify
which sites you wanted to go through.
You can even give it a TXT file full of
usernames that you wanted to search. And
to top it all off, you can even search
through NSFW websites. And to install
it, we can either just copy this pipx
install sherlockproject or we can just
go to our terminal or terminal and type
pip install sherlock.
For me, it says the requirements already
satisfied cuz I already installed it.
But first, let me see the usage. Let's
see what we can do with Sherlock. You
type sherlock dash dash help and let's
just scroll up to see what we can do.
Usage sherlock. We have to type sherlock
and everything here within the square
brackets is optional. It's optional
parameters. We don't have to give them
except one, the username. We have
obviously have to give it the username
so you can search for something. So,
let's just try the most simplest option,
sherlock and then the username. Sherlock
and then for us, missfirewall.
Sherlock slowly goes through multiple
websites and check if it's available.
After it's finished, here we can see it
gave us 46 results back. It searched
through hundreds of sites and it found
46 results, 46 social media platforms or
platform platforms in general, that have
missed that firewall. In here we can see
sites like seven cups, airliners,
Discord,
Reddit,
YouTube, TryHackMe, which is kind of
cool. And then we can also do a full
file of usernames cuz maybe they have we
want to search their friends or their
family. And I already made a file so I
can show you guys firewall fam. dot txt.
And I here I have a bunch of usernames,
missfirewall, misterfirewall,
firewallthefam, firewallfather,
firewallkin. You get the point. To
search up multiple usernames in a file
we type Sherlock followed by dollar
sign. And then in and then in brackets
we type cat firewall fam. txt. And then
we type dash dash site. I'm not going to
go through all the websites, all the
usernames cuz it's going to be a lot a
lot of work for us. It's going to take a
long time. So I'm going to do dash dash
site. I'm going to specify YouTube cuz
if I go through all it's going to take a
long time. It's going to be too much.
And once it's done we got 16 results
back and we got all the links of their
accounts. But obviously Sherlock only
looks up their usernames on different
sites and doesn't really give us any
information on the sites.
But the good news, we have a tool just
for that called the maigret. Let me show
you guys. And here it is, maigret.
And here it is.
And here it is, maigret. When we scroll
down we see how it is.
First it searches up the username on the
site and then gathers information on the
sites.
To install this super easy we just do
pip install maigret. So let's go ahead
and copy that. Go to our terminal, open
a new one, clear this up, make it
bigger,
and then just run that, pip install
maigret. Then clear it up once again
once it's installed. Go back to the
site. And the usage is super simple. We
just type maigret and the username. So
maigret.
And I'm going to use who am I gang not
missfirewall cuz someone else might have
missfirewall and I don't want to show
their information here on the video. So
I'm going to use my username but you get
the idea. Who am I gang.
After After it's done here we can see it
went through 500 sites and it looks
pretty similar to Sherlock. But the
difference is that this is way more
information-rich. For example, here in
the GitHub, it's on my GitHub, not only
did it find my follower count, 67,
my following count, full name,
it also found my location, my
Germany. I literally live in Germany.
And this is super important for your
investigations, cuz you don't have to go
through each website and look at the
information yourself. You can just use
Myriad, and it just extracts all the
information itself. Okay, so now you've
seen exactly how easy this is to do. How
can you make sure it doesn't happen to
you? My number one tip is that you just
go on Google, type in your name, see
what results come up, look at the ones
you don't like. If it's one of your
social media accounts or your website,
just change it or private your social
media account. If it's something you
don't own, like you won a tournament on
a school 3 years ago, you don't want
your name being there, just email them
or DM them. I'm sure they'll gladly
remove it. With that being said, I hope
you enjoyed this video. Don't forget to
subscribe and join the Discord, link in
the description.
More transcripts
Explore other videos transcribed with YouTLDR.

Analyse spectrale de l'Occident : Fiodor Dostoievski
Rien ne veut rien dire · English

Confronto Entre Espadas - KingShot
Darling Games · Portuguese (Portugal, Brazil)

Hukum Acara Pidana - M. Fatahillah Akbar S.H L.LM
Kanal Pengetahuan FH UGM · English

الدرس 1 HD -كرسي الإمام مالك مادة الفقه المالكي الشيخ سعيد الكملي
M.A.T · Arabic

OUTLANDER Full movie
DF Entertainment · English

Gamificación, inteligencia artificial y herramientas digitales para enriquecer propuestas educativas
Fundación Movistar Argentina · Spanish

Full SS1 : Bốn Cô Chị Hoa Khôi Tranh Sủng Tôi | Bốn Lù Vietsub
Bốn Lù Vietsub · English

Kurikulum Merdeka Rangkuman Materi IPS Kelas 10 Tema 1 Sejarah Indonesia Manusia Ruang dan Waktu
Portal Edukasi · English

mekanisme kerja enzim dan Regulasi enzim - materi biologi sma kelas bab
Biologi Tv · English

MADA TRANCE Ft Dabzee | Pulimada Movie | Ak Sajan | Joju George | Aishwarya Rajesh |
Appu Pathu Pappu Production House · English

Arti Hospitality apa ya? Kamus #hotel #traveler #tourism #hospitality
Glosarium Online · English

Pr Rafael Santos - Jesus Chorou (Sexta Feira 10/10/14)
ow productions · Portuguese (Portugal, Brazil)
Get the TLDR of any YouTube video
Transcribe, summarize, and repurpose videos in 125+ languages — free, no signup required.