
gophoner checks whether a single phone number is registered on popular apps and websites simultaneously, built for authorized OSINT research and auditing your own digital footprint.
| Tool | M4elstr0m/gophoner — Go CLI/TUI that checks whether a phone number is registered on popular services, concurrently and silently |
| Category | OSINT / phone-number footprint enumeration |
| Primary Use | Auditing which accounts are linked to a phone number you own or are authorized to assess, via gophoner check or the interactive TUI |
| Safe Use | Personal OSINT hygiene (checking your own footprint), authorized security assessments, and educational research; consent-free checking of third-party numbers may violate ToS and local law |
| Telemetry Note | Requests carry randomized desktop browser fingerprints (TLS, User-Agent, Client Hints), and checks are silent toward the target phone; defenders observe this as patterned registration-check traffic at the service edge |
gophoner is a Go-based OSINT utility from M4elstr0m that answers a narrow but perennial question: is this phone number registered on a given set of popular services? Rather than probing hundreds of sites like sherlock or holehe do with usernames and emails, it focuses on phone numbers and runs every selected module in parallel, so a check costs roughly the latency of the slowest service rather than the sum of all of them. The repository sits at 39 stars, is written in Go, and targets Go 1.26+, which tells you it is a fresh, actively developed project rather than a relic.
Architecturally, the tool splits into two faces. gophoner check is the scripting-friendly CLI path, accepting a target number and module flags, while gophoner interactive opens a guided terminal UI — the topic tags (bubbletea, cobra, tui) confirm the stack: cobra for command parsing and bubbletea for the TUI layer. This dual design means the same module set serves both ad-hoc human investigation and pipeline automation, with --json emitting results as a single JSON object on stdout for downstream tooling to consume.
The v1.0.0 module roster covers Amazon, Microsoft, Facebook, Google, and OpenAI, with commented-out badges in the README hinting that Telegram, Signal, Instagram, and Snapchat are queued for future releases. Five modules sounds thin compared to username enumerators, but phone-number registration endpoints are a much scarcer resource; landing on five major providers at once is what makes the tool useful in practice. The roadmap explicitly promises more modules and floats a plug-in system.
A notable design decision is what the README calls silent-by-default behavior: none of the current modules trigger an SMS, email, or notification to the target handset during a check. This is a meaningful operational property, because the classic risk with phone-based lookups is that password-reset or registration probes alert the number's owner. The author commits to calling out explicitly any future module that does notify the target, which is a good disclosure practice worth watching as the module list grows.
The engineering quality extends to how requests leave the machine. Each check uses randomized browser fingerprinting — an internally consistent TLS profile, User-Agent, and Client Hints combination drawn from a pool of real desktop browsers. This is a step above the plain net/http default fingerprint that most Go scrapers ship with, and it matters for both reliability (fewer bot blocks) and for understanding what the tool looks like from the service side: ordinary desktop traffic rather than an obvious scripted client.
Privacy-conscious logging is another deliberate choice. Target phone numbers are never written to the log file unless the operator passes --debug, and --no-log disables logging entirely. For anyone running this against their own numbers in a shared environment — a red team operator on an engagement laptop, or a researcher on a lab box — that default reduces the chance of sensitive identifiers leaking into artifacts that outlive the session. Combine it with --no-update if you also want to suppress the startup release check.
Scope limitation is baked into the architecture rather than left to policy alone. gophoner checks one phone number per invocation against your chosen modules, and the README is explicit that it is not built for bulk enumeration or sweeping number ranges — while honestly acknowledging that a wrapper script around the CLI could still automate that. This single-target-per-run design, plus the PolyForm Internal Use License 1.0.0 (which forbids redistribution and offering it as a hosted service), signals a tool intended for individual operators, not farming infrastructure.
Installation is straightforward across platforms. On any system with Go 1.26+, go install github.com/M4elstr0m/gophoner/cmd/gophoner@latest builds the binary; Windows users can use winget install M4elstr0m.gophoner and macOS users brew install --cask M4elstr0m/tap/gophoner, with an AUR package still marked as work in progress. Prebuilt binaries for Windows, Linux, and macOS are listed as a feature, and gophoner version verifies a successful install.
The usage surface is minimal by design: gophoner help, gophoner interactive, and the check command accepting a target number with -A to select all modules. The roadmap's CLI quality-of-life items — progress bar (already shipped), positive-results-only display, progressive result rendering — indicate the author is actively polishing the operator experience rather than dumping a research prototype.
The credits section is candid about lineage: the author names sherlock and holehe as prior art in single-credential, multi-service checking, and ignorant as the first phone-number tool found in the same space. The origin story — built after the author watched repeated 3 AM login attempts against one of their own accounts — frames gophoner as a defensive-footprint tool first. That framing is consistent with the Legal & Ethical Use section, which permits security research, personal OSINT hygiene, and education, and warns that consent-free checks may breach service ToS and local privacy, stalking, or harassment laws.
From a defensive perspective, gophoner is best understood as a meter for phone-number attack surface. Knowing which of Amazon, Microsoft, Facebook, Google, and OpenAI have an account bound to a given number tells you where that number is a viable account-recovery pivot — exactly the concern that motivated the tool's creation. Security teams can use it on corporate-issued numbers to inventory exposure, and service operators should recognize its traffic pattern: coordinated registration-check probes with rotating, internally consistent desktop fingerprints.
For professionals who need this capability inside an authorized workflow, gophoner earns its place through concurrency, JSON output, silent checks, and fingerprint randomization — the four properties that separate a considered tool from a quick script. The restrictive license, single-target scope, and explicit legal framing make its intended use unambiguous. As the module list grows toward the commented-out messengers and social platforms, it is worth tracking the repository's release notes to see whether the silent-by-default guarantee holds across every new module.
M4elstr0m/gophoner.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.