Which Websites Use the Password Recovery Method in Holehe?

Holehe uses the "password recovery" method on four specific websites: Adobe, Odnoklassniki, Samsung, and Mail.RU.

Holehe is an open-source OSINT tool that checks whether an email address is registered on various online services. According to the megadose/holehe source code, most modules employ registration-based or login-based checks, but a distinct subset uses the password recovery method to verify account existence and retrieve partial account information.

What Is the Password Recovery Method in Holehe?

The password recovery method works by calling a service's "forgot password" endpoint and analyzing the response. This technique can reveal:

  • Whether the email is linked to an existing account
  • Masked recovery email addresses
  • Masked phone numbers associated with the account

In the Holehe codebase, each module declares its technique through a method variable. When method = "password recovery", the module follows this flow instead of standard registration or login checks.

Services That Use Password Recovery in Holehe

Based on the current megadose/holehe repository, four modules explicitly set method = "password recovery":

Service Module Path Domain
Adobe holehe/modules/software/adobe.py adobe.com
Odnoklassniki holehe/modules/social_media/odnoklassniki.py ok.ru
Samsung holehe/modules/products/samsung.py samsung.com
Mail.RU holehe/modules/mails/mail_ru.py mail.ru

Adobe

In holehe/modules/software/adobe.py, the module sends a request to Adobe's password recovery endpoint. The response indicates account existence and may expose masked recovery information.

Odnoklassniki

The holehe/modules/social_media/odnoklassniki.py module targets the Russian social network Odnoklassniki (ok.ru). Its password recovery flow returns clues about linked phone numbers and alternative emails.

Samsung

Located at holehe/modules/products/samsung.py, this module checks Samsung accounts through their password reset mechanism. Samsung's response often includes partial phone number disclosure.

Mail.RU

The holehe/modules/mails/mail_ru.py module queries Mail.RU's recovery endpoint. As a major email provider, this check can reveal significant account metadata through recovery prompts.

How to Use These Modules

Each password recovery module follows Holehe's standard async pattern. Here's a complete working example:

import trio
import httpx

# Import password recovery modules

from holehe.modules.software.adobe import adobe
from holehe.modules.social_media.odnoklassniki import odnoklassniki
from holehe.modules.products.samsung import samsung
from holehe.modules.mails.mail_ru import mail_ru


async def check_password_recovery_methods():
    email = "target@example.com"
    results = []
    client = httpx.AsyncClient()
    
    # Check Adobe

    await adobe(email, client, results)
    
    # Check Odnoklassniki

    await odnoklassniki(email, client, results)
    
    # Check Samsung

    await samsung(email, client, results)
    
    # Check Mail.RU

    await mail_ru(email, client, results)
    
    await client.aclose()
    
    # Filter to password recovery methods only

    for item in results:
        print(f"{item['name']}: {item['domain']}")
        print(f"  Method: {item['method']}")
        print(f"  Account exists: {item['exists']}")
        if item.get('emailrecovery'):
            print(f"  Recovery email: {item['emailrecovery']}")
        if item.get('phoneNumber'):
            print(f"  Phone: {item['phoneNumber']}")
        print()


trio.run(check_password_recovery_methods)

Output Structure

Each password recovery module returns a dictionary with these keys:

  • name — Module identifier (e.g., "adobe")
  • domain — Target domain
  • method — Always "password recovery" for these modules
  • exists — Boolean indicating account registration status
  • emailrecovery — Masked recovery email or None
  • phoneNumber — Masked phone number or None

Why Password Recovery Matters for OSINT

The password recovery method offers distinct advantages for email-based investigations:

  1. Lower detection risk — No failed login attempts that trigger security alerts
  2. Richer metadata — Recovery flows often expose partial contact information
  3. Broader coverage — Some services only expose account existence through recovery endpoints

However, this method depends on each service's specific implementation. Rate limiting and response changes can affect reliability.

Summary

Frequently Asked Questions

How does Holehe's password recovery method differ from other checking methods?

Most Holehe modules use registration-based or login-based detection. The password recovery method specifically calls forgot-password endpoints, which can return account metadata without triggering failed login alerts. According to the megadose/holehe source, only the four modules listed above implement this technique.

Can I add password recovery support for other services to Holehe?

Yes. To implement password recovery for a new service, create a module that sets method = "password recovery" and implements the async function signature module_name(email, client, out). Study the existing implementations in adobe.py or mail_ru.py for request patterns and response parsing logic.

What information can password recovery modules expose beyond account existence?

The password recovery method in Holehe can extract masked recovery emails and masked phone numbers when services include these in their recovery responses. Adobe and Samsung particularly tend to expose partial phone numbers, while Mail.RU may reveal alternative email addresses linked to the account.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →