mirror of
https://github.com/0xZDH/o365spray
synced 2026-06-08 10:07:16 +00:00
Fix variable name typos
- Handle emptied user lists during spraying - Fix invalid data type
This commit is contained in:
+4
-2
@@ -1,7 +1,9 @@
|
||||
# CHANGELOG
|
||||
|
||||
## v2.0.2 (20/07/2021)
|
||||
- Add O365 reporting API password spraying module based on [Daniel Chronlund's blog post](https://danielchronlund.com/2020/03/17/azure-ad-password-spray-attacks-with-powershell-and-how-to-defend-your-tenant/) and [the ADFSpray tool](https://github.com/xFreed0m/ADFSpray).
|
||||
## v2.0.2
|
||||
- Add O365 reporting API password spraying module based on [Daniel Chronlund's blog post](https://danielchronlund.com/2020/03/17/azure-ad-password-spray-attacks-with-powershell-and-how-to-defend-your-tenant/) and [the ADFSpray tool](https://github.com/xFreed0m/ADFSpray). (20/07/2021)
|
||||
- Fix typos in sprayer modules that caused errors. (01/08/2021)
|
||||
- Add handling if a spraying user list is cleared during a run it does not throw an error. (01/08/2021)
|
||||
|
||||
## v2.0.1 (15/07/2021)
|
||||
- Add oAuth2 user enumeration module based on [AADInternals](https://github.com/Gerenios/AADInternals)
|
||||
|
||||
@@ -517,6 +517,11 @@ def spray(args: argparse.Namespace, output_dir: str, enum: Enumerator):
|
||||
spray.shutdown()
|
||||
break
|
||||
|
||||
# Stop if there are no more users to spray
|
||||
if not spray.userlist:
|
||||
logging.debug("End of password spraying user list reached.")
|
||||
break
|
||||
|
||||
# https://stackoverflow.com/a/654002
|
||||
# https://docs.python.org/3/tutorial/controlflow.html#break-and-continue-statements-and-else-clauses-on-loops
|
||||
# Only executed if the inner loop did NOT break
|
||||
|
||||
@@ -301,7 +301,7 @@ class Sprayer(BaseHandler):
|
||||
raise ValueError("Locked account limit reached.")
|
||||
|
||||
# Build email if not already built
|
||||
email = self.helper.check_email(user, domain)
|
||||
email = self.HELPER.check_email(user, domain)
|
||||
|
||||
# Write the tested user
|
||||
tested = f"{email}:{password}"
|
||||
@@ -405,7 +405,7 @@ class Sprayer(BaseHandler):
|
||||
raise ValueError("Locked account limit reached.")
|
||||
|
||||
# Build email if not already built
|
||||
email = self.helper.check_email(user, domain)
|
||||
email = self.HELPER.check_email(user, domain)
|
||||
|
||||
# Write the tested user
|
||||
tested = f"{email}:{password}"
|
||||
@@ -416,7 +416,7 @@ class Sprayer(BaseHandler):
|
||||
|
||||
# Grab external headers from config.py
|
||||
headers = Defaults.HTTP_HEADERS
|
||||
headers["Accept"] = ("application/json",)
|
||||
headers["Accept"] = "application/json"
|
||||
headers["Content-Type"] = "application/x-www-form-urlencoded"
|
||||
data = {
|
||||
"resource": "https://graph.windows.net",
|
||||
@@ -563,7 +563,7 @@ class Sprayer(BaseHandler):
|
||||
"""
|
||||
try:
|
||||
# Build email if not already built
|
||||
email = self.helper.check_email(user, domain)
|
||||
email = self.HELPER.check_email(user, domain)
|
||||
|
||||
# Write the tested user
|
||||
tested = f"{email}:{password}"
|
||||
|
||||
Reference in New Issue
Block a user