Skip to content

Latest commit

 

History

7 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

IAmAdmin!

outdated but still works, just add more email/pass detections fields or convert to chromium version 97% more accurate and hits.
A fast, multi-threaded admin portal credential checker written in Go with Chrome TLS fingerprinting.

Features

  • Filters credentials to admin URLs only (admin., admin-, /admin)
  • Automatically cleans, deduplicates, and rewrites the input file
  • Chrome 133 TLS fingerprint via bogdanfinn/tls-client
  • Smart HTML form detection — finds email/password fields across any framework
  • Anti-CSRF token extraction (hidden inputs, meta tags, JS variables)
  • Follows POST redirects intelligently to judge the real landing page
  • 100+ fail/success patterns across 10 languages and major frameworks
  • Colored console output with live progress counter
  • Outputs hits to found.txt, per-site files in results/, and everything to all.log

Requirements

Installation

git clone https://github.com/yourname/go-portalscan
cd go-portalscan
go build -o portalscan ulp.go

Usage

preview

./portalscan -f credentials.txt -t 50

Or run without flags for interactive prompts:

./portalscan
Enter credentials file path: credentials.txt
Enter number of threads: 50

Flags

Flag Default Description
-f (prompt) Path to credentials file
-t (prompt) Number of concurrent threads
-o found.txt Output file for hits
-debug false Dump raw HTML responses to debug_*.html

Credential Format

One entry per line:

host:email:password

Example:

admin.example.com:user@example.com:password123
admin-panel.site.co.uk:admin@site.co.uk:secret

Lines that don't match admin., admin-, or /admin are removed automatically. Invalid hosts, bad TLDs, and duplicates are also stripped before scanning begins.

Output

File Contents
found.txt All hits — email:pass | url
results/valid_{host}.txt Per-site hits
all.log Every result (HIT / FAIL / SKIP / ERR)

Debug Mode

./portalscan -f credentials.txt -t 10 -debug

Dumps the raw GET response and failed POST responses to debug_*.html files for inspection.

Disclaimer: This tool is intended for educational purposes only. The author is not responsible for any misuse or damage caused by this program. Do not use against any system you do not have explicit permission to test.

About

a fast, multi-threaded admin portal credential checker written in go with chrome TLS fingerprinting

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages