Which Services Use the Login Endpoint Detection Method in Holehe?
Holehe identifies services employing the login endpoint detection method by scanning for modules that declare method = "login", triggering probes that check authentication endpoints for leaked login URLs across 19 platforms including Snapchat, Amazon, and WordPress.
The open-source OSINT tool Holehe (maintained in the megadose/holehe repository) maps each supported service to a specific detection strategy to identify account correlations via email addresses. When a module utilizes the login endpoint detection method, it instructs the core engine to issue targeted requests to authentication endpoints and analyze HTTP responses for exposed login pathways.
How the Login Endpoint Detection Method Works
Holehe’s modular architecture relies on a method attribute defined in each service module. When a python file contains method = "login", the central engine in holehe/core.py dispatches a specialized probe workflow rather than generic registration or password-reset checks.
The detection follows a four-step process:
- Construct a request targeting the service’s hard-coded or derived login URL.
- Send the request using Holehe’s async HTTP client defined in
holehe/instruments.py. - Inspect the response for indicators of exposed endpoints, such as HTTP 302 redirects to
/loginlocations, JSON fields wheretypecontains "login", or specific authentication headers. - Report a positive finding if the response confirms the login endpoint is accessible or leaked.
Services Using the Login Endpoint Detection Method
The current master branch contains 19 modules that declare method = "login". These services span social media, e-commerce, productivity suites, and content management systems.
Social Media Platforms
- Snapchat —
holehe/modules/social_media/snapchat.py - Patreon —
holehe/modules/social_media/patreon.py - Parler —
holehe/modules/social_media/parler.py - Bitmoji —
holehe/modules/social_media/bitmoji.py
E-Commerce and Shopping
- Amazon —
holehe/modules/shopping/amazon.py - eBay —
holehe/modules/shopping/ebay.py - Vivino —
holehe/modules/shopping/vivino.py
Productivity and Business Tools
- Evernote —
holehe/modules/productivity/evernote.py - Any.do —
holehe/modules/productivity/anydo.py - Eventbrite —
holehe/modules/products/eventbrite.py
Media and Content Management Systems
- Flickr —
holehe/modules/medias/flickr.py - Komoot —
holehe/modules/medias/komoot.py - WordPress CMS —
holehe/modules/cms/wordpress.py - Vox Media CMS —
holehe/modules/cms/voxmedia.py - Atlassian (ID) —
holehe/modules/cms/atlassian.py
Customer Relationship Management (CRM)
- HubSpot CRM —
holehe/modules/crm/hubspot.py - Axonaut CRM —
holehe/modules/crm/axonaut.py - AmoCRM —
holehe/modules/crm/amocrm.py
Email Services
- Yahoo Mail —
holehe/modules/mails/yahoo.py
Technical Implementation and Code Structure
The login endpoint detection logic is orchestrated by holehe/core.py, which imports each module and checks its method attribute before executing the appropriate probe. Helper functions for constructing requests and parsing responses reside in holehe/instruments.py.
Below is a minimal example demonstrating how the core engine runs the login-endpoint detection for a service like Snapchat:
import asyncio
from holehe.core import Holehe
from holehe.modules.social_media.snapchat import method, url
async def check_snapchat(email):
scanner = Holehe()
# The core knows that `method == "login"` → call the module’s login check
result = await scanner.run_module(email, "snapchat")
return result
# Example usage
if __name__ == "__main__":
email = "example@domain.com"
print(asyncio.run(check_snapchat(email)))
When executed with a valid email address, this script triggers the probe defined in snapchat.py, which examines the authentication response for login endpoint leaks and returns a dictionary indicating whether the endpoint was discovered.
Summary
- 19 services in the
megadose/holeherepository use the login endpoint detection method by declaringmethod = "login"in their respective modules. - Core dispatch logic resides in
holehe/core.py, which routes requests based on the method attribute. - Detection relies on analyzing HTTP 302 redirects, JSON response tokens, and authentication headers for signs of exposed login URLs.
- Modular structure allows each service to define specific endpoints in
holehe/modules/subdirectories (e.g.,social_media/,shopping/,crm/).
Frequently Asked Questions
What triggers the login endpoint detection method in Holehe?
The core engine checks the method variable in each service module; when set to "login", it triggers the specialized login-endpoint probe instead of registration or recovery checks. This attribute is defined at the module level in files like holehe/modules/social_media/snapchat.py.
How does Holehe determine if a login endpoint is leaked?
Holehe inspects HTTP responses for specific indicators including 302 redirects pointing to /login paths, JSON payloads where fields such as type contain the string "login", or distinctive authentication headers that expose the endpoint structure. These checks are implemented within each module’s response parsing logic.
Can I add a new service using the login endpoint detection method?
Yes, create a new Python file in the appropriate holehe/modules/ subdirectory (e.g., social_media/ or shopping/) and set method = "login" at the module level. Define the target URL and response validation logic following the pattern established in existing modules like amazon.py or evernote.py.
Is the login endpoint detection method different from other Holehe detection methods?
Yes, unlike methods that probe registration forms or password_reset endpoints, the login-specific approach targets the authentication gateway directly. It searches for scenarios where the service inadvertently exposes the login URL through response metadata, distinguishing it from methods that check for existing account disclosures via registration errors.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →