Files
site/content/blog/social-mapper-contribution/index.en.md
T
2026-10-10 20:20:21 +04:00

3.9 KiB
Raw Blame History

title, date, draft, tags, summary
title date draft tags summary
How I contributed to Social Mapper 2026-10-10T20:03:56+04:00 false
open-source
python
osint
selenium
Two pull requests to a 4000-star OSINT tool: I fixed Douban and moved the whole project to spaces

While going through old accounts, I came across my trail in Social Mapper. It's an OSINT tool by Jacob Wilkin (Greenwolf): it searches for people across social networks and uses facial recognition to stitch one person's profiles from different sites into a single report. Pentesters and red teams use it to build a list of a company's employees and their pages. The repository has over 4000 stars and 800 forks.

In September 2020 I sent it 20 commits in two pull requests, and I'm still listed as the third contributor by commit count, after the author's own two accounts. Here's what happened.

Douban

It all started with issue #166. The Chinese social network Douban stopped working: the module failed with HTTP 418, and it was unclear whether it had logged in or not. The issue had been open since April. The author replied that the site seemed to have changed, but he couldn't check because he couldn't find where to sign up.

Social Mapper works through Selenium and Firefox, so this was familiar territory for me. Douban had changed its page title and login form, and the module was looking for the old ones. In PR #193 I:

  • fixed the login for the new form and the title check
  • added a clear message when the login page doesn't load as expected, instead of failing silently
  • moved the Firefox and geckodriver paths into the FIREFOX_BINARY and GECKODRIVER environment variables, so they don't have to be on PATH
  • fixed several Python 3 bytes vs str errors in file reading and writing left over from the Python 2 days

The funny part is that I didn't have a Douban account either, so I couldn't fully test the login. I asked the issue author to clone my fork and switch to the branch with the fix.

While the PR was waiting for review, the author pushed a batch of his own fixes and missed mine. He apologized and asked me to resubmit. I resolved the conflicts, pinged him a day later, and the PR was merged on September 9.

Tabs and spaces

While digging through the code, I noticed that social_mapper.py used 4-space indentation while the other modules used tabs. In Python that's not cosmetic: mixed indentation breaks code or, worse, makes it misleading. I opened issue #195 and right away sent PR #196:

  • the whole project moved to 4 spaces, as PEP 8 recommends
  • string literals used as comments were replaced with real comments
  • the code was formatted to PEP 8 and unused imports were removed
  • added .gitignore and .editorconfig

In total: 11 files, +1657 and −1430 lines. The author merged it the same day, said I seemed to be on a coding spree, and asked whether I had any ideas on getting around Facebook's new rate limit. He also added me to the thanks list in the README, where I still am.

What I took away from it

Someone else's open source project turned out to be a great place to practice reading unfamiliar code and working with a maintainer. A small targeted fix that solves someone's problem gets accepted gladly. After that you can propose something bigger, like refactoring the whole project.

And yes, my Development Standards now say tabs instead of spaces. Six years later I changed my mind, but the main rule stayed the same: one indentation style per project, and a tool enforces it, not a person.

The project is no longer actively maintained, but the author still accepts pull requests. If you use it, do so only within legal penetration tests and with the client's consent.