Giter Club home page Giter Club logo

Comments (8)

TheToddLuci0 avatar TheToddLuci0 commented on May 28, 2024

Sending garbage in as a flow token doesn't seem to fix it. The actual token is generated client site in JS.

from credmaster.

knavesec avatar knavesec commented on May 28, 2024

Rare for me to see an issue from you without a PR, do you have any idea how to differentiate?

I'm a little confused by the two JSON objects, it seems like the first one is what you're saying needs to change (ifexistsresult 1) so we would need to figure out what the difference would be elsewise?

from credmaster.

TheToddLuci0 avatar TheToddLuci0 commented on May 28, 2024

Sorry man, I'm only human. I'll send some other PR (maybe add pet credmaster functionality?) to make up for it 😉

The issue seems to be that calling as credmaster does (without the other variables that are computed via clientside JS), you get "user not found" vs "user exists, but don't use a password". I haven't been able to figure out how to get that value correctly as of yet.

from credmaster.

TheToddLuci0 avatar TheToddLuci0 commented on May 28, 2024

The second JSON object where the correct result is retuned is from burp-proxying the request through the normal web flow

from credmaster.

knavesec avatar knavesec commented on May 28, 2024

Hahah, pet credmaster would be creepy but an invaluable contribution to the tool.

So are you saying that the clientside JS determines different request variables, which then impacts the response itself?

from credmaster.

ville87 avatar ville87 commented on May 28, 2024

Just as an input, not sure if it helps anything...
I used the tool with the o365 module against a list of test users with a valid password. All of them returned "FAILURE".
The response code 401 was returned for all requests (even though MFA excluded, correct password).
Using the module msol however worked and identified the correct credentials.
Maybe Microsoft changed something in the autodiscover url / endpoint so that this does not work anymore? If I have time for further debugging, I'll let you know.

from credmaster.

alecmoran1 avatar alecmoran1 commented on May 28, 2024

Yeah I just opened ann issue on that I belive it is because of AADSTS53003 or the CAP policy

from credmaster.

TwistedSim avatar TwistedSim commented on May 28, 2024

Just as an input, not sure if it helps anything... I used the tool with the o365 module against a list of test users with a valid password. All of them returned "FAILURE". The response code 401 was returned for all requests (even though MFA excluded, correct password). Using the module msol however worked and identified the correct credentials. Maybe Microsoft changed something in the autodiscover url / endpoint so that this does not work anymore? If I have time for further debugging, I'll let you know.

Microsoft disabled BasicAuth for all tenant, which the o365 plugin rely on.

from credmaster.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.