CTRL ALT ACT – Week 3: Targeting Shady Websites & Advanced OSINT
🔄 Quick Recap & Moving Forward
Hope you’ve been able to collect some basic intel on shady accounts and groups by now. If you’re still learning the ropes, that’s perfectly okay—there’s no rush. The goal here isn’t speed, it’s impact. Take your time, practice, build your skills, and revisit earlier exercises if needed.
In Week 2, we targeted miscreant accounts and groups.
Now, in Week 3, we’re stepping up. It’s time to target websites.
This is where things get interesting. If you’re into ethical hacking or digital investigations, this week will give you a bit more room to explore. 😉
🎯 Objective of the Week
Let’s be real: we all know there are websites out there hosting illegal, harmful, or non-consensual content. Whether it's leaks, manipulated NSFW content, or media meant to harass or exploit—this is your chance to contribute by collecting, reporting, and (where possible) helping to take them down or disrupt access.
Important: This task is not against NSFW content in general, but strictly against content that is illegal, non-consensual, or harmful. Also, while the focus examples may lean on NSFW sites, these methods apply to other shady or harmful websites too.
If these harmful websites can't be fully stopped, then we must at least make it harder to access them.
🛡️ Step 1: Stay Safe
- Use TOR or a trusted VPN
- Avoid using your personal identity or accounts
- Work in Incognito/Private mode
- Clear your cache & history after each session
🕵️♀️ Step 2: Discovering Harmful Sites
Find & Explore
- Think like a regular user — the way you’d search for content late at night 😉
- Use specific keywords or combinations you know are used in shady circles (e.g., “leak,” “private video,” “xxx group,” “illegal download” etc.)
- Explore connected or linked sites — many are part of larger networks
Example (Focus: NSFW Leak Website)
- You find a website that hosts explicit content
- You scroll and come across content that looks non-consensual or manipulated
- Document it:
- Take a screenshot with URL visible (or just copy the URL if privacy is a concern)
- Look for usernames, timestamps, titles, or any hint of origin
🚨 Step 3: Reporting
Basic reporting:
- Look for report buttons or contact options on the website
- Submit URLs and explain briefly what you found
Advanced reporting:
- Use platforms like cybercrime.gov.in (India) or equivalents in your country
- Refer back to the reporting steps shared in Week 2
🔍 Step 4: OSINT on Websites
Now the real work begins.
A. Using Google Dorking
Think of Google Dorks as incantations — speak the right syntax and Google spills its darkest secrets. Here's your spellbook:
| 🧙 Syntax | 🎯 Use | 💥 Examples |
|---|---|---|
site: |
Limit results to one domain or TLD | site:pastebin.com passwords — credential dumps on Pastebinsite:.xyz inurl:leak — shady .xyz media hosting sites |
inurl: |
Find pages with keywords in the URL | inurl:"illegal streaming" — piracy sites with "illegal streaming" right in their address (not subtle)inurl:admin login — exposed admin login panels begging to be brute-forced (don't) |
intext:(or inbody:) |
Search for words in the page body | intext:"private video" filetype:mp4 — non-consensual mediaintext:"credit card" "expiry" "cvv" — people selling CC data openly. Yes, it's that dumb. |
filetype: |
Restrict results to a specific file format | filetype:pdf "confidential" "salary" — leaked HR docsfiletype:sql "INSERT INTO" "password" — exposed database dumps. Free data breach just sitting there. |
intitle: |
Match keywords in the page title | intitle:"index of" mp4 — open directory listings full of videosintitle:"webcam" "login" "admin" — unprotected security cameras. People really out here broadcasting their living rooms. |
"" + AND / OR |
Combine terms for precision hunting | "free download" AND ("cracked" OR "warez") — piracy hubs (half of them are honeypots; don't click, just screenshot)"buy fake" OR "counterfeit" inurl:forum — black market forums where people trade everything from fake passports to bad life choices |
⚠️ Important: These searches are for documentation and reporting only. Do not interact, download, or exploit anything you find. Your role is to observe, document, and contribute to ethical takedowns. Touching the hot stove is optional — and stupid.
B. Collect Technical Evidence
- Screenshot key pages
- Note all URLs and domains
- Check the source of uploaded content (user, profile, timestamp, etc.)
- Visit linked domains or redirecting versions
🧠 Step 5: Technical OSINT (Trace Website Ownership)
- WHOIS Lookup
- Use tools like who.is or ICANN Lookup
- Look for: name, phone, email, hosting provider
- Pivot from Data
- Found a phone number? Use reverse lookup tools
- Found an email? Check for linked accounts, breaches, or social media
- Found an IP? Use IP geolocation or hosting info tools
- Use OSINT Framework
- Look for Similar Sites
- Many illegal sites operate in networks
- Use structural similarities or shared content to identify clones or backups
- Build a Map
- Create a small diagram or document to track how sites are connected, who runs what, and where you can intervene
- Compile Your Report
- Include screenshots, URLs, WHOIS data, and links to reports you filed
- Share with trusted organizations, cybercrime units, or relevant NGOs
📺 Beginner's intro to website OSINT
⚠️ Notes & Tips
- Do not engage with website operators directly
- Preserve your anonymity and data security
- Use burner accounts or anonymous email addresses when reporting
- Some sites may use CDN or cloud services to hide real IPs — use traceroute tools for deeper analysis
🔬 Step 6: Advanced Analysis – Tracing Content
Sometimes you’ll come across identifiable people or places in the content. Here’s how to handle it:
- Face is visible? Use reverse image search, face recognition tools, or people search engines
- Background visible?
🔍 Every detail matters. A shadow, a poster, a light pole—don’t overlook anything.
🧑💻 Bonus: What Can Ethical Hackers Do?
Curious about going deeper? Here's what each question actually means — with pointers so you're not just staring at the screen like a confused golden retriever:
- What info can you extract from the site's IP?
→ Throw it into Shodan. You'll get hosting provider, location, open ports, and sometimes other domains on the same server. One IP, dozens of shady sites = pattern. - Found an email? Can it be spoofed or monitored?
→ Check Have I Been Pwned for breach history. Cross-reference on social media. An email linked to 3 different scam sites is a gift-wrapped connection. - What's the tech stack?
→ Use BuiltWith or Wappalyzer. Old WordPress + vulnerable plugins = the digital equivalent of leaving your front door open with a neon "FREE STUFF" sign. - Scan it with Nmap
→ Open ports tell you what services are running. Port 22 (SSH)? Port 3306 (MySQL)? If they're exposed to the internet, that's negligence, not a challenge for you to exploit. Document it. - Can you access the admin page?
→ Try/admin,/wp-admin,/login. If it's unprotected, screenshot it, report it. Then pat yourself on the back for being the adult in the room. - Intercepting traffic with Burp Suite
→ See what data the site sends and receives. Sometimes the backend leaks emails, API keys, or internal paths. Again — observe, document, don't be a idiot.
📺 Beginner's intro to website hacking
⚠️ Reminder: This is for awareness and ethical research only. Unauthorized access is illegal. Don't be the reason we have to add another warning section.
📚 Useful Tools & Resources
- TOR Browser
- Google Hacking Database (GHDB)
- Who.is (WHOIS Lookup)
- Have I Been Pwned (email breach check)
- Shodan (IoT & Website Scanner)
- Cybercrime Reporting Portal (India)
Let's be real for a second. Week 3 is where most people tap out. Not because it's hard — but because it requires actually doing things.
- Did you try at least 3 Google dorks from the table above?
- Did you run a WHOIS lookup on a domain?
- Did you document everything in your OSINT diary?
If you skipped any of this, you're cheating yourself, not us. The whole point of this module is that you walk away with real skills, not just the memory of having scrolled through some HTML. Go back. Do the work. Future you will thank present you.
✍️ Final Words
Remember, this work is challenging but essential. Targeting harmful websites isn't just about investigation — it's about making the internet safer for everyone. Stay safe, work smart, and report responsibly.
Good luck, and if you need help, just ask — but try first. Please.
🚀 Ready for Week 4?
In the next week, we’ll focus on how to properly compile your findings, structure professional OSINT reports, and learn where and how to submit them effectively for action. Whether it's law enforcement, NGOs, or platforms—get ready to turn research into impact.
← Previous: Week 2 – Dummy Accounts & Targeting Miscreant Profiles Next: Week 4 – Report Making & Submissions →