This commit is contained in:
Octoberfest7
2023-07-10 15:07:58 -04:00
parent c5fb827d79
commit 4e34fce51c
2 changed files with 22 additions and 4 deletions
+11
View File
@@ -96,6 +96,8 @@ TeamsPhisher requires that users have a Microsoft Business account (as opposed t
This means you will need an AAD tenant and at least one user with a corresponding license. At the time of publication, there are some free trial licenses available in the AAD license center that fulfill the requirements for this tool.
You will need to log into the personal Sharepoint of the user you are going to be sending messages with at least once prior to using the account with TeamsPhisher. This should be something like tenantname-my.sharepoint.com/personal/myusername_mytenantname_onmicrosoft_com or tenantname-my.sharepoint.com/personal/myusername_mytenantname_mycustomdomain_tld.
In terms of local requirements, I recommend updating to the latest version of Python3. You will also need Microsoft's authentication library:
```
pip3 install msal
@@ -278,6 +280,15 @@ Fixed a few comments and re-ordered some steps in main to now check for requisit
## v1.1.1
Minor fixes
## v1.1.2
Fixed an error users were reporting in regards to uploading the attachment to Sharepoint; this stemmed from naming/renaming conventions that happen when users use custom domain with their tenants.
Added a verification check to ensure that if users are using a NON @domain.onmicrosoft.com domain that they also use the -s switch in order to specify their sharepoint site manually to avoid issues.
Updated setup section to include logging into Sharepoint at least once prior to using TeamsPhisher as a user identified that not having logged in before with the account would cause TeamsPhisher to fail.
Added &top=999 parameter to getSenderInfo web request to increase the number of users retrieve per page/decrease number of requests required to find our user
### Reverse change regarding parsing of '.' in usernames when assembling Sharepoint uri
v.1.1 changed how usernames with the '.' character in them were parsed for the purposes of creating the requisite Sharepoint URI's. There were several distinct issues going on and I mistakenly identified this as the cause of one of them. This change has been reverted. The result is that a username like tom.jones@mytest.onmicrosoft.com will now have a sharepoint uri assembled as "tom_jones_mytest_onmicrosoft_com" rather than "tom.jones_mytest_onmicrosoft_com".
+11 -4
View File
@@ -24,7 +24,7 @@ useragent = "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gec
fd = None
# version: TeamsPhisher version used in banner
__version__ = "1.1.1"
__version__ = "1.1.2"
def p_err(msg, exit):
output = Fore.RED + "[-] " + msg + Style.RESET_ALL
@@ -210,7 +210,7 @@ def getSenderInfo(bearer):
while True:
url = "https://teams.microsoft.com/api/mt/emea/beta/users"
if skipToken:
url += f"?skipToken={skipToken}"
url += f"?skipToken={skipToken}&top=999"
response = requests.get(url, headers=headers)
@@ -594,6 +594,13 @@ if __name__ == "__main__":
args = parser.parse_args()
# Ensure that if a non *.onmicrosoft.com domain was used that use has also specified -s switch
# When a user has specified a custom domain (e.g. mytesttenant.com), the sharepoint will still live at whatever the initial .onmicrosoft.com domain was (e.g. mytesttenant.onmicrosoft.com)
# However the sharepoint uri will now be user_mytesttesnant_com instead of user_mytesttenant_onmicrosoft_com
# The full thing for user@mytesttenant.com should now be https://mytesttenant-my.sharepoint.com/personal/user_mytesttenant_com/...
if "onmicrosoft.com" not in args.username and not args.sharepoint:
p_err("If your tenant uses a custom domain (e.g. username is NOT myusername@*.onmicrosoft.com) you must use the -s switch and manually specify your sharepoint site name!", True)
# If logging, open file and write commandline + banner
if args.log:
dt = datetime.datetime.now()
@@ -691,10 +698,10 @@ if __name__ == "__main__":
# If user-specified sharepoint was provided, assemble using that value otherwise do so using senderInfo
if args.sharepoint:
senderSharepointURL = "https://%s-my.sharepoint.com" % (args.sharepoint)
senderDrive = "%s_%s_onmicrosoft_com" % (args.username.split("@")[0].replace(".", "_").lower(), args.sharepoint)
else:
senderSharepointURL = "https://%s-my.sharepoint.com" % senderInfo.get('tenantName')
senderDrive = senderInfo.get('userPrincipalName').replace("@", "_").replace(".", "_").lower()
senderDrive = args.username.replace("@", "_").replace(".", "_").lower()
# Upload file to sharepoint that will be sent as an attachment in chats
uploadInfo = uploadFile(sharepointToken, senderSharepointURL, senderDrive, args.attachment)