Full Transcript

·YouTLDR

How Hackers Find Anyone's Info From Just Their Instagram...

12:26EnglishTranscribed Jul 26, 2026
0:00

Watch this. I'm going to take this

0:01

Instagram handle, just one username, and

0:03

I'll get her real name, the city she

0:05

lives in, her phone number, and every

0:08

other account she's ever made online. I

0:10

got all of this through OSINT, open

0:12

source intelligence. Basically, all the

0:14

public information that's out there

0:16

about you online, scattered across the

0:18

internet. And I'm going to be showing

0:20

you exactly how it's done. But before we

0:22

go any further, everything I'm about to

0:24

show you on this video is done on my own

0:25

accounts. Don't do this with malicious

0:27

intent. OSINT by itself is legal, but

0:30

the second you start using it to stalk,

0:32

harass, or even scam someone, that's

0:34

where you cross the line and it becomes

0:36

illegal. Let's begin. The first tool I

0:38

want to show you guys here is called

0:39

OSINTGram, and it's pretty popular. It

0:41

has 12,000 stars on GitHub, and it does

0:44

one thing very well. You give it one

0:45

single Instagram username, and it pulls

0:48

back everything Instagram is publicly

0:50

leaking on that account. Without wasting

0:52

much time, let's just scroll down and

0:53

begin with the installation. And we can

0:54

either just clone this right here and

0:55

paste it in our terminal, or we can go

0:57

up here and click the big green button

0:59

and copy the web URL, then go to our

1:01

terminal and just type git clone, and

1:03

then paste in the web URL we just

1:04

copied. And while this is cloning,

1:06

scroll down and hit the subscribe

1:07

button. I would really appreciate it.

1:09

Once done, we CD into the tool, CDO, and

1:12

then tab to fill it out by itself. Press

1:14

enter. Let's list the Let's clear this

1:16

up first and then list the files. And

1:17

here inside the tool, we can see a bunch

1:19

of files and folders, and one of them is

1:21

requirements.txt.

1:23

This means we have a bunch of

1:24

dependencies to install so this tool can

1:26

run smoothly without any errors. And

1:28

also in the installation guide right

1:29

here, we see we first need to make a

1:30

virtual environment to install the

1:32

dependencies. So we copy this and we

1:33

just paste it in our terminal. Hit

1:35

enter. Now we load the virtual

1:36

environment that we just created. And to

1:38

do that, we go to the installation page

1:39

again, and in the fourth section, load

1:41

the virtual environment. If you're on

1:43

Windows, you use this command right

1:44

here, but since I'm on Kali Linux, I use

1:46

a source to activate it. I'll copy this

1:48

section, then paste it in my terminal.

1:49

Right click, paste to clipboard. And by

1:51

this part right here, you know it loaded

1:53

successfully. Now all that's left to do

1:54

is going to the dependencies. To to the

1:57

requirements of Instasheck. To do that,

1:58

we just copy right pip install -r

2:00

requirements.txt. We copy it, paste on

2:02

terminal, standard, and it takes a bit

2:04

to install. After it's done, we clean up

2:06

the terminal so it's nice and clean. And

2:08

now we're almost done, but there's one

2:10

more thing. We need to pull the data

2:11

somehow from Instagram. And then the

2:13

sixth step, right over here, open the

2:14

credentials.ini file in the config

2:17

folder. Let's go ahead and do that real

2:18

quick. There's the files, we can click

2:20

that inside config, list the files

2:22

again, and here we see it,

2:23

credentials.ini. Nano credentials and we

2:27

tab. Inside we have three fields,

2:29

username, password, and hiker_api_token.

2:33

There's two ways we can pull the data.

2:34

Either we log in into our normal

2:36

Instagram account using our username and

2:38

password, or use the hiker API token. In

2:41

my opinion, using your own Instagram

2:42

account is a very bad idea because

2:44

Instagram is very aggressive and cracks

2:46

down on bots. And as soon as the tool

2:48

starts pulling data, the Instagram is

2:50

going to think this account is a bot,

2:52

either going to lock it or ban it

2:53

completely. So, we should go with the

2:55

hiker API token. We get the token or the

2:57

access key that we need directly from

2:58

the website, and it says in the

3:00

paragraph right here, use hiker API

3:01

token from the website. Right click,

3:04

open new tab. First 100 requests are

3:06

free after registration and confirmation

3:08

with your Telegram. Let me show you.

3:10

When you go to the site, you get

3:11

redirected to the tokens page. And I

3:13

already did it and I'm all logged in,

3:14

and here's my access key, my token that

3:16

I need. Don't try to use it, it's going

3:17

to be deleted after this video. But once

3:19

you're here, scroll down, go to the

3:21

Telegram page, and just verify with the

3:23

bot, do /start. Once you're verified,

3:25

come here and you're going to have your

3:26

access key here. And in your terminal,

3:28

just go ahead and paste in your token

3:29

you just got, and then save it and exit.

3:31

Let's just clear the whole thing up, and

3:33

now we're set up and ready to go. And

3:34

for the last step, all we have to do is

3:35

just run the main file, main.py. So,

3:38

python3 main.py and target username, the

3:41

Instagram username of the target, to

3:43

spawn interactive prompt. Let's go ahead

3:45

and do that. So, python3

3:47

main.

3:48

py and the target username, the

3:51

Instagram account that I definitely

3:52

didn't made up. It's not one of my

3:53

alternate account named miss.firewall.

3:58

Yeah, when I made this account I thought

4:00

the username would be pretty funny. Now

4:01

it's just kind of cringe. I can't lie.

4:03

But let's just send it.

4:04

Uh it's in config folder. Let's just

4:06

exit it.

4:07

And then clear it again and let's run it

4:09

again. python3 main.py

4:12

miss

4:13

firewall

4:15

After it ran, we can see right here it

4:17

connected to the Highker API first and

4:19

then it found the target miss firewall

4:21

and then her Instagram ID.

4:23

Scrolling down, we first have to type

4:24

list to show all the commands we can

4:26

run. So let's just do that. list

4:29

And you can see a bunch of commands

4:31

starting from address, get all

4:32

registered address by the target photos,

4:34

clear cache with the tool, a bunch of

4:36

stuff. But first, let's just run info to

4:38

get basic information on the target.

4:40

info

4:41

And here we have some information again,

4:42

basic ones like the ID of the Instagram,

4:45

full name miss firewall, her bio hello,

4:47

my name is miss firewall. Miss fire I

4:50

must have misspelled it. And this is my

4:52

personal blog.

4:54

Followers zero, he has four followers,

4:56

two photos, two photos posted, business

4:58

account. It is a business account since

5:00

it is a personal blog.

5:02

Verified account false and here we have

5:04

her HD profile picture, a full HD

5:06

profile picture of uh

5:08

her profile.

5:09

And here we have it, her profile

5:10

picture. It's a um girl with a firewall

5:13

face.

5:15

Anyways, let's just move on to the next

5:16

one.

5:17

Let's do something like address. Get all

5:19

registered addresses by the target

5:21

photos. addrs And here, woohoo, we found

5:25

one addresses. One post with an address

5:28

and the address right here.

5:29

But she probably didn't give her full

5:31

address on the post. And we can see

5:32

right here, let me go out to the to the

5:34

profile. Instagram miss.firewall I'm

5:37

already logged in so I can show you

5:38

guys. And here we have the post and in

5:40

the location it says Anthony, Texas.

5:43

But why does it say a full address in

5:44

our terminal?

5:46

What most people don't know that

5:48

these these locations right here users

5:50

create them. Normal users like you and

5:52

me.

5:52

And then when they create them, they

5:54

first have to drop a pin on an exact

5:56

location. Then they can name that

5:57

location whatever like Anthony, Texas.

6:00

When a user goes to create a post,

6:02

Instagram suggests the closest pin near

6:05

that person.

6:06

It might say Anthony, Texas, but behind

6:08

that is an exact location, exact

6:10

address, a pin. So when the user was

6:12

choosing a location and saw Anthony,

6:14

Texas, she was like, "Yeah, that's where

6:16

I'm at the right now. I'm going to

6:17

choose it." Without knowing that in the

6:19

background, she actually doxxed herself

6:21

and gave out her full location. And then

6:23

we can go ahead and actually copy this

6:24

location and then go to our Google Maps

6:26

so I can show you. google.com/maps

6:29

and then we go ahead and paste in our

6:30

location we just copied.

6:33

And then we see the pin right here.

6:35

This address is showing to this location

6:36

right here, RV Jones Colina.

6:39

And when we go back to Instagram page,

6:40

here we see a sign, "Welcome to Texas."

6:43

Let us search up for that sign to see

6:44

exactly where it is.

6:45

Our address that we extracted is right

6:47

here. Let's go look up for the sign,

6:49

"Welcome to Texas" sign.

6:53

Our pin is right here and the "Welcome

6:54

to Texas" sign is right here. So she

6:56

took her picture here, then went on

6:57

Instagram to post it, searched up for a

6:59

location, Instagram saw the nearest pin

7:02

to her was named Anthony, Texas,

7:04

suggested it to her. She thought, "Yeah,

7:06

that's where I'm at, Anthony, Texas. I'm

7:08

going to choose it." Without thinking

7:09

much, but in the background, she

7:11

actually doxxed herself. Now let's try

7:13

something else. Let's try something like

7:15

following email. She doesn't have

7:17

followers, let's try following email.

7:18

This gets all the emails of users

7:20

followed by the target.

7:22

Let's copy that

7:24

and then paste it right in. And here we

7:25

got a three out of four emails from her

7:27

following list from Hack The Box,

7:29

Network Chuck, and David Bombal. These

7:31

were the first people that came to mind

7:32

when I first made the account, but

7:34

that's beside the point. What we got

7:36

here is super important during an

7:38

information gathering because now we

7:39

have leverage. We have something we can

7:41

pivot to when we hit a roadblock or a

7:43

wall. Now, we can always send nice

7:45

personalized

7:46

emails or DMs pretending to be Miss

7:48

Firewall to our friends. Let's imagine

7:50

these are our friends.

7:51

And now we can do for example hash tags

7:54

and get some hashtags on her posts. For

7:55

example, farm girl, family, Texas, road

7:58

trips. So, now we know she likes road

8:00

trips, she's a farm girl, she lives in

8:02

Anthony, Texas, and we can make nice

8:05

personalized DMs or emails to her

8:07

friends pretending to be her so we can

8:09

get her even more information on her.

8:11

Now, since we mapped out where she's

8:12

been, her friends, her hobbies, the most

8:15

obvious thing would be to look for

8:17

different accounts so we can extract

8:18

more information. And the tool for that

8:20

is Sherlock. I've already covered it in

8:22

one of my other OSINT videos, but I'm

8:24

going to cover it again.

8:25

And what it does is it that simple. You

8:27

give it a single username and it looks

8:29

through over 400 websites to check if

8:31

that username exists. You can also give

8:34

it multiple usernames, you can specify

8:36

which sites you wanted to go through.

8:38

You can even give it a TXT file full of

8:40

usernames that you wanted to search. And

8:42

to top it all off, you can even search

8:44

through NSFW websites. And to install

8:46

it, we can either just copy this pipx

8:48

install sherlockproject or we can just

8:50

go to our terminal or terminal and type

8:51

pip install sherlock.

8:54

For me, it says the requirements already

8:56

satisfied cuz I already installed it.

8:57

But first, let me see the usage. Let's

8:59

see what we can do with Sherlock. You

9:00

type sherlock dash dash help and let's

9:03

just scroll up to see what we can do.

9:05

Usage sherlock. We have to type sherlock

9:07

and everything here within the square

9:08

brackets is optional. It's optional

9:10

parameters. We don't have to give them

9:12

except one, the username. We have

9:14

obviously have to give it the username

9:15

so you can search for something. So,

9:16

let's just try the most simplest option,

9:18

sherlock and then the username. Sherlock

9:21

and then for us, missfirewall.

9:24

Sherlock slowly goes through multiple

9:25

websites and check if it's available.

9:27

After it's finished, here we can see it

9:29

gave us 46 results back. It searched

9:31

through hundreds of sites and it found

9:33

46 results, 46 social media platforms or

9:36

platform platforms in general, that have

9:38

missed that firewall. In here we can see

9:40

sites like seven cups, airliners,

9:43

Discord,

9:45

Reddit,

9:46

YouTube, TryHackMe, which is kind of

9:48

cool. And then we can also do a full

9:50

file of usernames cuz maybe they have we

9:53

want to search their friends or their

9:54

family. And I already made a file so I

9:56

can show you guys firewall fam. dot txt.

10:01

And I here I have a bunch of usernames,

10:02

missfirewall, misterfirewall,

10:04

firewallthefam, firewallfather,

10:06

firewallkin. You get the point. To

10:07

search up multiple usernames in a file

10:09

we type Sherlock followed by dollar

10:11

sign. And then in and then in brackets

10:13

we type cat firewall fam. txt. And then

10:18

we type dash dash site. I'm not going to

10:20

go through all the websites, all the

10:22

usernames cuz it's going to be a lot a

10:23

lot of work for us. It's going to take a

10:25

long time. So I'm going to do dash dash

10:26

site. I'm going to specify YouTube cuz

10:28

if I go through all it's going to take a

10:29

long time. It's going to be too much.

10:30

And once it's done we got 16 results

10:32

back and we got all the links of their

10:34

accounts. But obviously Sherlock only

10:36

looks up their usernames on different

10:37

sites and doesn't really give us any

10:39

information on the sites.

10:41

But the good news, we have a tool just

10:43

for that called the maigret. Let me show

10:45

you guys. And here it is, maigret.

10:47

And here it is.

10:48

And here it is, maigret. When we scroll

10:50

down we see how it is.

10:52

First it searches up the username on the

10:53

site and then gathers information on the

10:55

sites.

10:56

To install this super easy we just do

10:57

pip install maigret. So let's go ahead

10:59

and copy that. Go to our terminal, open

11:01

a new one, clear this up, make it

11:03

bigger,

11:04

and then just run that, pip install

11:06

maigret. Then clear it up once again

11:07

once it's installed. Go back to the

11:09

site. And the usage is super simple. We

11:10

just type maigret and the username. So

11:13

maigret.

11:15

And I'm going to use who am I gang not

11:17

missfirewall cuz someone else might have

11:19

missfirewall and I don't want to show

11:20

their information here on the video. So

11:22

I'm going to use my username but you get

11:23

the idea. Who am I gang.

11:26

After After it's done here we can see it

11:28

went through 500 sites and it looks

11:31

pretty similar to Sherlock. But the

11:33

difference is that this is way more

11:34

information-rich. For example, here in

11:36

the GitHub, it's on my GitHub, not only

11:37

did it find my follower count, 67,

11:40

my following count, full name,

11:42

it also found my location, my

11:45

Germany. I literally live in Germany.

11:47

And this is super important for your

11:48

investigations, cuz you don't have to go

11:49

through each website and look at the

11:51

information yourself. You can just use

11:52

Myriad, and it just extracts all the

11:53

information itself. Okay, so now you've

11:55

seen exactly how easy this is to do. How

11:58

can you make sure it doesn't happen to

11:59

you? My number one tip is that you just

12:01

go on Google, type in your name, see

12:03

what results come up, look at the ones

12:05

you don't like. If it's one of your

12:06

social media accounts or your website,

12:08

just change it or private your social

12:09

media account. If it's something you

12:11

don't own, like you won a tournament on

12:13

a school 3 years ago, you don't want

12:15

your name being there, just email them

12:16

or DM them. I'm sure they'll gladly

12:18

remove it. With that being said, I hope

12:19

you enjoyed this video. Don't forget to

12:21

subscribe and join the Discord, link in

12:22

the description.

More transcripts

Explore other videos transcribed with YouTLDR.

Get the TLDR of any YouTube video

Transcribe, summarize, and repurpose videos in 125+ languages — free, no signup required.

Try YouTLDR Free