top of page
Writer's picturealvin gitonga

Twitter-Hacking using Twint šŸ¦…

Welcome back Cyber warriors šŸ’Ŗ. Today, Twitter!


Ā 

šŸ¤Œ On September 7, 2011, Twitter announced that it had 100 million active users logging in at least once a month and 50 million active users every day. On March 31, 2014, Twitter announced that there were 255 million monthly active users (MAUs) and 198 million mobile MAUs šŸ¤­.As of Q1 2019, Twitter had more than 330 million monthly active users šŸ™†ā€ā™€ļø.


Today we will using a tool Twint, to scrape info on anyone we want on twitter, all we will need is their username šŸ‘Œ and we can access their entire twitter history without using twitter or needing to have an account whatsoever šŸŒ¹

Twint utilizes Twitterā€™s search operators to let you scrape Tweets from specific users šŸ˜², scrape Tweets relating to certain topics, hashtags & trends, or sort out sensitive information from Tweets like e-mail and phone numbers šŸ•µļøā€ā™‚ļø . I find this very useful, and you can get really creative with it too. Twint also makes special queries to Twitter allowing you to also scrape a Twitter user's followers, Tweets a user has liked, and who they follow without any authentication, API, Selenium, or browser emulation šŸ„·


Some of the benefits of using Twint vs Twitter API šŸ¤Œ:

  • Can fetch almost all Tweets (Twitter API limits to last 3200 Tweets only);

  • Fast initial setup;

  • Can be used anonymously and without Twitter sign up;

  • No rate limitations.

Ā 

So Cyber Morans, fire up your Kali Linux boxes and lets get cracking šŸ’Ŗ


Installation šŸš€

Open a new terminal on your linux machine and run:

after the download in complete; cd twint to get into the folder then,

pip3 install . -r requirements.txt

or

pip3 install twint

CLI Use: Basic Examples and Combos šŸ¦‰

  • šŸ‘‰twint -u username - Scrape all the Tweets of a user (doesn't include retweets but includes replies).

  • šŸ‘‰twint -u username -s pineapple - Scrape all Tweets from the user's timeline containing pineapple.

  • šŸ‘‰twint -s pineapple - Collect every Tweet containing pineapple from everyone's Tweets.

  • šŸ‘‰twint -u username --year 2014 - Collect Tweets that were tweeted before 2014.

  • šŸ‘‰twint -u username --since "2015-12-20 20:30:15" - Collect Tweets that were tweeted since 2015-12-20 20:30:15.

  • šŸ‘‰twint -u username --since 2015-12-20 - Collect Tweets that were tweeted since 2015-12-20 00:00:00.

  • šŸ‘‰twint -u username -o file.txt - Scrape Tweets and save to file.txt.

  • šŸ‘‰twint -u username -o file.csv --csv - Scrape Tweets and save as a csv file.

  • šŸ‘‰twint -u username --email --phone - Show Tweets that might have phone numbers or email addresses.

  • šŸ‘‰twint -s "NelsonHavi" --verified - Display Tweets by verified users that Tweeted about Nelson Havi.

.

  • šŸ‘‰twint -g="48.880048,2.385939,1km" -o file.csv --csv - Scrape Tweets from a radius of 1km around a place in Paris and export them to a csv file.

  • šŸ‘‰twint -u username -es localhost:9200 - Output Tweets to Elasticsearch

  • šŸ‘‰twint -u username -o file.json --json - Scrape Tweets and save as a json file.

  • šŸ‘‰twint -u username --database tweets.db - Save Tweets to a SQLite database.

  • šŸ‘‰twint -u username --followers - Scrape a Twitter user's followers.

  • šŸ‘‰twint -u username --following - Scrape who a Twitter user follows.

  • šŸ‘‰twint -u username --favorites - Collect all the Tweets a user has favorited (gathers ~3200 tweet).

  • šŸ‘‰twint -u username --following --user-full - Collect full user information a person follows

  • šŸ‘‰twint -u username --timeline - Use an effective method to gather Tweets from a user's profile (Gathers ~3200 Tweets, including retweets & replies).

  • šŸ‘‰twint -u username --retweets - Use a quick method to gather the last 900 Tweets (that includes retweets) from a user's profile.

  • šŸ‘‰twint -u username --resume resume_file.txt - Resume a search starting from the last saved scroll-id.

  • šŸ‘‰twint -u noneprivacy --csv --output none.csv --lang en --translate --translate-dest it --limit 100 - get 100 english tweets and translate them to italian.

Twitter can shadow-ban accounts, which means that their tweets will not be available via search. To solve this, pass --profile-full if you are using Twint via CLI or, if are using Twint as module, add config.Profile_full = True. Please note that this process will be quite slow.

Ā 

Twint can be imported as a library on a python script to fully automate this process. Lemme show you.

still on that terminal, type nano twintexample.py and hit enter;

This opens a text editor (nano) where we will write some python šŸ code šŸ‘‡

when you hit enter šŸ‘‡

Now lets write some python šŸ code; We will be searching a web developer and tech memelord on twitter kirinyetbrian and we will be looking for all his tweets with the term 'dev' in them.


PS: šŸ”„ You can use any twitter username you want as long as you have permission. This is because this tool will scrape tweets from private and none private users as well those that have blocked you šŸ”„


We will import twint and use variable 'c', assign that to the twint.Config() function (It's in the twint lib we imported first) so to assign the script's search parameters (as args) and then call the function at the end. dont forget the (c) - these are the function's arguments.


ctrl + x to exit nano

y then enter to save script

Now lets run it šŸ‘‰ python3 Twintexample1.pyšŸ‘‡;

Unfortunately ā›ˆļø, i cannot show the results here since I DONT have Brian's permission. However, run it yourself, use it on other users and even enhance the script to do more than that. You can get creative with this tool like using it to track insightment of violence or continue to monitor people who have blocked or are private.

I personally use it to look for events using a key word like 'hatupangwingwi' to track UDA campaigns across twitter (purely for oversight) or search key phrases to uncover malicious campaigns like fake forex exchange promotions, trace and track misinformation campaigns etc. Twint's power is your imagination. Try more and have fun with other šŸ scripts like;

This outputs the results into a .csv file šŸ‘†

This translates the first 100 tweets from English to Italian šŸ‘†

Ā 

Conclusion

Twint can be used to scrape information on twitter regardless their privacy settings. It can be useful to relentlessly pursue some malicious activities, by law enforcement šŸ‘®ā€ā™‚ļø to try and gather information, hold hate-speech accountable, trace the origins šŸ•µļøā€ā™€ļø and spread of misinformation ...etc.

Thank you for your time, Like and leave a comment/review and as always. I will see you in the next one but till then, stay awesome! šŸ‘Š šŸ’Ŗ


21 views0 comments

Recent Posts

See All

Comments


Post: Blog2_Post
bottom of page