-
-
Notifications
You must be signed in to change notification settings - Fork 2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
New Phishlet: Outlook Web Access #212
base: master
Are you sure you want to change the base?
Conversation
Outlook Web Access phishlet. Just substitute "subdomain" and "domain.tld" with actual target. Regex for password was required to match only on the string "password" as OWA also has a "passwordText" parameter in the POST request that was overwriting the password capture value.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is a boilerplate phishlet with little to no changes...
Correct, it is mostly boilerplate, but there 2 specific differences that would reduce troubleshooting and level of effort for others.
|
@swarleysez Ok, I guess I just would suggest writing instructions if you aren't planning on including a domain. |
Ah, I see where there could be confusion with that. For anyone reading this; the OWA domain is almost always unique to the organization's domain and subdomain (i.e. owa.github.com, mail.amazon.com, etc.), hence the ambiguous "subdomain.domain.tld" in the phishlet. I will look at adding some comments to make the insertion points clearer. |
do you have one working for outlook as of today? i am getting this error: #248 |
why i get unauthorized request after enable the phishlets |
Can you add some comments with instructions in the phishlet file on how and where to modify the hostname? |
New Phishlet: Outlook Web Access