forked from mikepound/pwned-search
-
Notifications
You must be signed in to change notification settings - Fork 0
/
pwned.mos
executable file
·41 lines (35 loc) · 1.1 KB
/
pwned.mos
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
#!/bin/bash
# FAIR License, Copyright (c) 2019 72Zn
# Usage of the works is permitted provided that this instrument is retained
# with the works, so that any entity that uses the works is notified of this
# instrument.
# DISCLAIMER: THE WORKS ARE WITHOUT WARRANTY.
# usage examples:
# ./pwned.mos [pw1] [pw2] ...
# ./pwned.mos < <file_with_passwords>
# echo pw | ./pwned.mos
PWNAPI="https://api.pwnedpasswords.com/range"
lookup_pwned_api() {
local pass="$1"
local pwhash=$(printf "%s" "$pass" | shasum -a 1 | cut -d" " -f1)
local curlrv="$(curl -s "$PWNAPI"/"${pwhash:0:5}")"
[ -z "$curlrv" ] && echo "$pass could not be checked" && return
local result="$(echo "$curlrv" | grep -i "${pwhash:5:35}")"
if [ -n "$result" ]; then
local occ="$(printf "%s" "${result}" | cut -d: -f2 | sed 's/[^0-9]*//g')"
printf "%s was found with %s occurances (hash: %s)\n" "$pass" "$occ" "$pwhash"
else
printf "%s was not found\n" "$pass"
fi
}
if [ "$#" -lt 1 ]; then
# read from file or stdin
while read -r pw; do
lookup_pwned_api $pw
done
else
# read arguments
for pw in "$@"; do
lookup_pwned_api $pw
done
fi