outdated but still works, just add more email/pass detections fields or convert to chromium version 97% more accurate and hits.
A fast, multi-threaded admin portal credential checker written in Go with Chrome TLS fingerprinting.
- Filters credentials to admin URLs only (
admin.,admin-,/admin) - Automatically cleans, deduplicates, and rewrites the input file
- Chrome 133 TLS fingerprint via
bogdanfinn/tls-client - Smart HTML form detection — finds email/password fields across any framework
- Anti-CSRF token extraction (hidden inputs, meta tags, JS variables)
- Follows POST redirects intelligently to judge the real landing page
- 100+ fail/success patterns across 10 languages and major frameworks
- Colored console output with live progress counter
- Outputs hits to
found.txt, per-site files inresults/, and everything toall.log
git clone https://github.com/yourname/go-portalscan
cd go-portalscan
go build -o portalscan ulp.go./portalscan -f credentials.txt -t 50Or run without flags for interactive prompts:
./portalscan
Enter credentials file path: credentials.txt
Enter number of threads: 50| Flag | Default | Description |
|---|---|---|
-f |
(prompt) | Path to credentials file |
-t |
(prompt) | Number of concurrent threads |
-o |
found.txt |
Output file for hits |
-debug |
false |
Dump raw HTML responses to debug_*.html |
One entry per line:
host:email:password
Example:
admin.example.com:user@example.com:password123
admin-panel.site.co.uk:admin@site.co.uk:secret
Lines that don't match admin., admin-, or /admin are removed automatically. Invalid hosts, bad TLDs, and duplicates are also stripped before scanning begins.
| File | Contents |
|---|---|
found.txt |
All hits — email:pass | url |
results/valid_{host}.txt |
Per-site hits |
all.log |
Every result (HIT / FAIL / SKIP / ERR) |
./portalscan -f credentials.txt -t 10 -debugDumps the raw GET response and failed POST responses to debug_*.html files for inspection.
Disclaimer: This tool is intended for educational purposes only. The author is not responsible for any misuse or damage caused by this program. Do not use against any system you do not have explicit permission to test.
