feat: post about contributing to Social Mapper
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
a4d92fecd3
commit
56371a2019
2 files changed
+98
No files matched your search
@@ -0,0 +1,49 @@
|
|||||||
|
---
|
||||||
|
title: "How I contributed to Social Mapper"
|
||||||
|
date: 2026-10-10T20:03:56+04:00
|
||||||
|
draft: false
|
||||||
|
tags:
|
||||||
|
- open-source
|
||||||
|
- python
|
||||||
|
- osint
|
||||||
|
- selenium
|
||||||
|
summary: "Two pull requests to a 4000-star OSINT tool: I fixed Douban and moved the whole project to spaces"
|
||||||
|
---
|
||||||
|
|
||||||
|
While going through old accounts, I came across my trail in [Social Mapper](https://github.com/Greenwolf/social_mapper). It's an OSINT tool by Jacob Wilkin (Greenwolf): it searches for people across social networks and uses facial recognition to stitch one person's profiles from different sites into a single report. Pentesters and red teams use it to build a list of a company's employees and their pages. The repository has over 4000 stars and 800 forks.
|
||||||
|
|
||||||
|
In September 2020 I sent it 20 commits in two pull requests, and I'm still listed as the third contributor by commit count, after the author's own two accounts. Here's what happened.
|
||||||
|
|
||||||
|
## Douban
|
||||||
|
|
||||||
|
It all started with [issue #166](https://github.com/Greenwolf/social_mapper/issues/166). The Chinese social network Douban stopped working: the module failed with HTTP 418, and it was unclear whether it had logged in or not. The issue had been open since April. The author replied that the site seemed to have changed, but he couldn't check because he couldn't find where to sign up.
|
||||||
|
|
||||||
|
Social Mapper works through Selenium and Firefox, so this was familiar territory for me. Douban had changed its page title and login form, and the module was looking for the old ones. In [PR #193](https://github.com/Greenwolf/social_mapper/pull/193) I:
|
||||||
|
|
||||||
|
- fixed the login for the new form and the title check
|
||||||
|
- added a clear message when the login page doesn't load as expected, instead of failing silently
|
||||||
|
- moved the Firefox and geckodriver paths into the `FIREFOX_BINARY` and `GECKODRIVER` environment variables, so they don't have to be on `PATH`
|
||||||
|
- fixed several Python 3 `bytes` vs `str` errors in file reading and writing left over from the Python 2 days
|
||||||
|
|
||||||
|
The funny part is that I didn't have a Douban account either, so I couldn't fully test the login. I asked the issue author to clone my fork and switch to the branch with the fix.
|
||||||
|
|
||||||
|
While the PR was waiting for review, the author pushed a batch of his own fixes and missed mine. He apologized and asked me to resubmit. I resolved the conflicts, pinged him a day later, and the PR was merged on September 9.
|
||||||
|
|
||||||
|
## Tabs and spaces
|
||||||
|
|
||||||
|
While digging through the code, I noticed that `social_mapper.py` used 4-space indentation while the other modules used tabs. In Python that's not cosmetic: mixed indentation breaks code or, worse, makes it misleading. I opened [issue #195](https://github.com/Greenwolf/social_mapper/issues/195) and right away sent [PR #196](https://github.com/Greenwolf/social_mapper/pull/196):
|
||||||
|
|
||||||
|
- the whole project moved to 4 spaces, as PEP 8 recommends
|
||||||
|
- string literals used as comments were replaced with real comments
|
||||||
|
- the code was formatted to PEP 8 and unused imports were removed
|
||||||
|
- added `.gitignore` and `.editorconfig`
|
||||||
|
|
||||||
|
In total: 11 files, +1657 and −1430 lines. The author merged it the same day, said I seemed to be on a coding spree, and asked whether I had any ideas on getting around Facebook's new rate limit. He also added me to the thanks list in the README, where I still am.
|
||||||
|
|
||||||
|
## What I took away from it
|
||||||
|
|
||||||
|
Someone else's open source project turned out to be a great place to practice reading unfamiliar code and working with a maintainer. A small targeted fix that solves someone's problem gets accepted gladly. After that you can propose something bigger, like refactoring the whole project.
|
||||||
|
|
||||||
|
And yes, my [Development Standards](/code-style.md) now say tabs instead of spaces. Six years later I changed my mind, but the main rule stayed the same: one indentation style per project, and a tool enforces it, not a person.
|
||||||
|
|
||||||
|
The project is no longer actively maintained, but the author still accepts pull requests. If you use it, do so only within legal penetration tests and with the client's consent.
|
||||||
@@ -0,0 +1,49 @@
|
|||||||
|
---
|
||||||
|
title: "Как я контрибьютил в Social Mapper"
|
||||||
|
date: 2026-10-10T20:03:56+04:00
|
||||||
|
draft: false
|
||||||
|
tags:
|
||||||
|
- open-source
|
||||||
|
- python
|
||||||
|
- osint
|
||||||
|
- selenium
|
||||||
|
summary: "Два пулл-реквеста в OSINT-инструмент на 4000 звезд: починил Douban и перевел весь проект на пробелы"
|
||||||
|
---
|
||||||
|
|
||||||
|
Разбирал старые аккаунты и наткнулся на свой след в [Social Mapper](https://github.com/Greenwolf/social_mapper). Это OSINT-инструмент Джейкоба Уилкина (Greenwolf): он ищет людей по соцсетям и через распознавание лиц склеивает профили одного человека с разных сайтов в один отчет. Его используют пентестеры и red team, чтобы собрать список сотрудников компании и их страниц. У репозитория больше 4000 звезд и 800 форков.
|
||||||
|
|
||||||
|
В сентябре 2020 года я прислал туда 20 коммитов в двух пулл-реквестах и до сих пор числюсь третьим по количеству коммитов, после двух аккаунтов самого автора. Расскажу, что там было.
|
||||||
|
|
||||||
|
## Douban
|
||||||
|
|
||||||
|
Все началось с [issue #166](https://github.com/Greenwolf/social_mapper/issues/166). Китайская соцсеть Douban перестала работать: модуль падал с HTTP 418 и было непонятно, залогинился он или нет. Issue висел с апреля, автор ответил, что сайт, похоже, поменялся, но проверить не может, потому что не нашел, где там регистрироваться.
|
||||||
|
|
||||||
|
Social Mapper работает через Selenium и Firefox, так что для меня это была знакомая территория. Douban поменял заголовок страницы и форму входа, а модуль искал старые. В [PR #193](https://github.com/Greenwolf/social_mapper/pull/193) я:
|
||||||
|
|
||||||
|
- поправил вход под новую форму и проверку заголовка
|
||||||
|
- добавил понятное сообщение, если страница входа загрузилась не так, как ожидается, вместо молчаливого падения
|
||||||
|
- вынес пути к Firefox и geckodriver в переменные окружения `FIREFOX_BINARY` и `GECKODRIVER`, чтобы не держать их строго в `PATH`
|
||||||
|
- починил несколько ошибок Python 3 с `bytes` и `str` при чтении и записи файлов, которые остались после перехода с Python 2
|
||||||
|
|
||||||
|
Самое забавное, что у меня тоже не было аккаунта на Douban, поэтому проверить вход до конца я не мог. Попросил автора issue склонировать мой форк и переключиться на ветку с фиксом.
|
||||||
|
|
||||||
|
Пока PR ждал ревью, автор запушил пачку своих исправлений и пропустил мой. Извинился и попросил перевыложить. Я разрешил конфликты, через день напомнил о себе, и 9 сентября PR влили.
|
||||||
|
|
||||||
|
## Табы и пробелы
|
||||||
|
|
||||||
|
Пока разбирался в коде, заметил, что `social_mapper.py` написан с отступом в 4 пробела, а остальные модули табами. В Python это не косметика: смешанные отступы ломают код или, что хуже, делают его обманчивым. Завел [issue #195](https://github.com/Greenwolf/social_mapper/issues/195) и сразу прислал [PR #196](https://github.com/Greenwolf/social_mapper/pull/196):
|
||||||
|
|
||||||
|
- весь проект переведен на 4 пробела, как рекомендует PEP 8
|
||||||
|
- строковые литералы, которые использовались вместо комментариев, заменены на нормальные комментарии
|
||||||
|
- код отформатирован по PEP 8, лишние импорты удалены
|
||||||
|
- добавлены `.gitignore` и `.editorconfig`
|
||||||
|
|
||||||
|
Итого 11 файлов, +1657 и −1430 строк. Автор влил его в тот же день, написал, что я, похоже, вошел в раж, и спросил, нет ли у меня идей, как обойти новый rate limit Facebook. А еще добавил меня в список благодарностей в README, где я и вишу до сих пор.
|
||||||
|
|
||||||
|
## Что я из этого вынес
|
||||||
|
|
||||||
|
Чужой открытый проект оказался отличным местом, чтобы потренироваться читать незнакомый код и общаться с мейнтейнером. Маленький точечный фикс, который решает чью-то проблему, принимают охотно. А после него можно предлагать и что-то крупнее, вроде рефакторинга всего проекта.
|
||||||
|
|
||||||
|
И да, сейчас в моих [Стандартах разработки](/code-style.md) записаны табы вместо пробелов. Спустя 6 лет я поменял мнение, но главное правило осталось прежним: в одном проекте один стиль отступов, и следит за ним инструмент, а не человек.
|
||||||
|
|
||||||
|
Сейчас проект не поддерживается активно, но автор принимает пулл-реквесты. Если пользуетесь им, используйте только в рамках легальных пентестов и с согласия заказчика.
|
||||||
Reference in new issue
Block a user