Octoberfest7 / TeamsPhisher

Send phishing messages and attachments to Microsoft Teams users
989 stars 128 forks source link

Splashscreen Bypass Patched #34

Open pwnf opened 1 month ago

pwnf commented 1 month ago

Looks like the splash screen bypass has once again been patched by Microsoft reducing the effectiveness of TeamsPhisher.

Now when you remove the victim from the group they are only able to preview the message and the button for clicking through the splash screen is greyed out.

Given reliance is once again on the user to click through the splash screen and they can't be removed - I do wonder if its better to revert TeamsPhisher back to just messaging a user without adding them to a group at all.

Octoberfest7 commented 1 month ago

There is a 'revert_bypass' branch I threw together for this purpose a bit ago. I'll merge it in eventually, along with addressing outstanding pull requests, hopefully in the near future after some other work is complete.