Understanding the Password Recovery Method in Holehe Modules

The Password Recovery Method in Holehe modules indicates that a service-specific checker verifies email registration by invoking the target platform’s password-reset endpoint, extracting account-existence signals and recovery metadata without requiring authentication credentials.

Holehe is an open-source reconnaissance tool developed by megadose that identifies whether an email address is registered across hundreds of online services. Each module defines a method variable that documents the specific technique used to probe the service. When method is set to "password recovery", the module leverages the target’s account-recovery flow to safely determine registration status.

What Is the Password Recovery Method?

The Password Recovery Method is a passive reconnaissance technique that exploits the standard password-reset functionality exposed by most web platforms. Instead of attempting authentication with guessed credentials—which could trigger security alerts—the module submits the target email to the service’s "Forgot Password" API endpoint.

This approach works because password-recovery endpoints typically validate the supplied email before proceeding. If the address exists in the system, the response often leaks metadata such as:

  • A masked secondary recovery email (e.g., ****@adobe.com)
  • A partially redacted phone number (e.g., +1‑555‑***‑1234)
  • A clear boolean flag indicating account existence

By parsing these responses, Holehe determines account presence without ever needing the actual password.

How Modules Declare This Method

Every Holehe module that utilizes this technique explicitly declares the strategy at the module level. In the source code, this appears as a simple string assignment:

method = "password recovery"

This metadata is subsequently collected by the core engine in holehe/core.py and included in the final report to inform the analyst how the result was obtained.

How the Password Recovery Method Works in Practice

When executing a check, the module builds an HTTP request targeting the service’s password-reset API. The request mimics legitimate browser behavior, including appropriate headers and CSRF tokens where required. Upon receiving the response, the module parses the JSON or HTML content for indicators of account validity.

According to the megadose/holehe source code, modules using this method return a standardized dictionary containing keys such as exists, emailrecovery, and phoneNumber. For example, the Adobe module extracts masked recovery emails from the password-reset response, while the Samsung module captures phone number fragments.

Implementation Examples from the Holehe Source

The repository contains multiple implementations of the Password Recovery Method, each tailored to the specific API structure of the target service.

Adobe Module

In holehe/modules/software/adobe.py, the module interacts with Adobe’s identity management endpoints. It submits the target email to the password-recovery flow and parses the response to extract masked recovery addresses. The module sets:

method = "password recovery"

This allows the tool to confirm Adobe account existence and retrieve partial recovery metadata without authentication.

Odnoklassniki (OK.ru) Module

The holehe/modules/social_media/odnoklassniki.py module targets the Russian social network OK.ru. It invokes the platform’s password-reset endpoint to check registration status. The response handling logic determines whether the email is associated with an active profile, returning the result alongside the "password recovery" method identifier.

Samsung Module

Located at holehe/modules/products/samsung.py, this module probes Samsung’s account services. It leverages the electronics manufacturer’s password-recovery API to verify if an email is linked to a Samsung Account, extracting any recovery phone numbers or secondary emails disclosed during the process.

Running Modules That Use Password Recovery

You can execute these checks via the command line or programmatically using Python’s asyncio.

Command Line Execution

To run Holehe from the terminal and see which services utilize the password recovery flow:

holehe -u example@example.com

Typical output excerpt showing the method classification:


[+] adobe.com (password recovery)
    → Exists: true
    → Recovery e‑mail: ****@adobe.com
    → Phone: +1‑555‑***‑1234

Programmatic Usage

Developers can import individual modules directly to inspect the method metadata:

import asyncio
import aiohttp
from holehe.modules.software.adobe import adobe

async def check_adobe(email):
    async with aiohttp.ClientSession() as client:
        out = []
        await adobe(email, client, out)
        return out[0]

# Execute the check

result = asyncio.run(check_adobe('test@example.com'))
print(result['method'])        # → "password recovery"

print(result['exists'])        # → True or False

print(result['emailrecovery']) # → masked secondary email (if available)

Summary

Frequently Asked Questions

What does the password recovery method detect in Holehe?

The password recovery method detects whether an email address is registered on a target service by analyzing the response from the platform’s password-reset endpoint. It captures boolean existence flags and may extract masked recovery information such as partial email addresses or phone numbers.

Is the password recovery method safe to use without credentials?

Yes, the password recovery method is designed to operate without authentication. It only invokes public password-reset APIs that are accessible to unauthenticated users, making it a passive reconnaissance technique that does not trigger account lockouts or login attempt alerts.

How does holehe/core.py utilize the method metadata?

The holehe/core.py file imports each service module, executes its async checking function, and collects the returned dictionary. It specifically captures the method key to label each result in the final output, allowing users to understand which verification technique was employed for each service.

Why do some services reveal account information during password recovery?

Services reveal limited account metadata during password recovery to help users identify their accounts and select appropriate recovery options. However, this design choice creates an information disclosure vulnerability that reconnaissance tools like Holehe exploit to confirm account existence without requiring the actual password.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →