Fix variable name typos

- Handle emptied user lists during spraying
- Fix invalid data type
This commit is contained in:
ZDH
2021-08-01 22:13:47 -04:00
parent 8ba1a3287c
commit 26ba53bf7d
3 changed files with 13 additions and 6 deletions
+4 -2
View File
@@ -1,7 +1,9 @@
# CHANGELOG
## v2.0.2 (20/07/2021)
- Add O365 reporting API password spraying module based on [Daniel Chronlund's blog post](https://danielchronlund.com/2020/03/17/azure-ad-password-spray-attacks-with-powershell-and-how-to-defend-your-tenant/) and [the ADFSpray tool](https://github.com/xFreed0m/ADFSpray).
## v2.0.2
- Add O365 reporting API password spraying module based on [Daniel Chronlund's blog post](https://danielchronlund.com/2020/03/17/azure-ad-password-spray-attacks-with-powershell-and-how-to-defend-your-tenant/) and [the ADFSpray tool](https://github.com/xFreed0m/ADFSpray). (20/07/2021)
- Fix typos in sprayer modules that caused errors. (01/08/2021)
- Add handling if a spraying user list is cleared during a run it does not throw an error. (01/08/2021)
## v2.0.1 (15/07/2021)
- Add oAuth2 user enumeration module based on [AADInternals](https://github.com/Gerenios/AADInternals)
+5
View File
@@ -517,6 +517,11 @@ def spray(args: argparse.Namespace, output_dir: str, enum: Enumerator):
spray.shutdown()
break
# Stop if there are no more users to spray
if not spray.userlist:
logging.debug("End of password spraying user list reached.")
break
# https://stackoverflow.com/a/654002
# https://docs.python.org/3/tutorial/controlflow.html#break-and-continue-statements-and-else-clauses-on-loops
# Only executed if the inner loop did NOT break
+4 -4
View File
@@ -301,7 +301,7 @@ class Sprayer(BaseHandler):
raise ValueError("Locked account limit reached.")
# Build email if not already built
email = self.helper.check_email(user, domain)
email = self.HELPER.check_email(user, domain)
# Write the tested user
tested = f"{email}:{password}"
@@ -405,7 +405,7 @@ class Sprayer(BaseHandler):
raise ValueError("Locked account limit reached.")
# Build email if not already built
email = self.helper.check_email(user, domain)
email = self.HELPER.check_email(user, domain)
# Write the tested user
tested = f"{email}:{password}"
@@ -416,7 +416,7 @@ class Sprayer(BaseHandler):
# Grab external headers from config.py
headers = Defaults.HTTP_HEADERS
headers["Accept"] = ("application/json",)
headers["Accept"] = "application/json"
headers["Content-Type"] = "application/x-www-form-urlencoded"
data = {
"resource": "https://graph.windows.net",
@@ -563,7 +563,7 @@ class Sprayer(BaseHandler):
"""
try:
# Build email if not already built
email = self.helper.check_email(user, domain)
email = self.HELPER.check_email(user, domain)
# Write the tested user
tested = f"{email}:{password}"