cardi / proofpoint-url-decoder

tools to mess around with proofpoint URLs
Creative Commons Zero v1.0 Universal
18 stars 4 forks source link

Cisco secure web? #9

Open agenbite opened 3 days ago

agenbite commented 3 days ago

Damn. My employer has changed the "secure" links provider, and now it's Cisco. The URLs have the following shape:

https://secure-web.cisco.com/1W9jhe2SGm2BNitIIaautca8rNFg8x1HzdiXH2nqdTHek8f3H2xv8js8dm9EVu3HRSeIAkMj6c2zwWFmrcG8XKsupK8sSz5j8Zog1At25XnpzkZ6gPXk6y_O4oqFgmV_OesoEEurqTsYFv_GeckTqxJ5ThIWtTBbiLD1r4AX8PGJuDI7rRGT22a-W8kVsXnYUr1LvMrOQnSufLQ5EJ3Fb95jONCil7uSQ_e0YNOA0ErMVvlvOQis-bWdOSNxEXZU1st6Ud_NKGOudW7_GI7IK_FYfJl3j-gkbzf25eF2X1KI/https%3A%2F%2Fmailchi.mp%2Fenqa%2Fenqa-bulletin-jun2024%3Fe%3D65775e6286

Looks to me that they are easier to spot than Proofpoint's, but my absolute lack of regex knowledge won't allow me to filter them adecuately. Is there any chance to add these type of urls to the url-decoder?

cardi commented 3 days ago

While I don't have any emails that use Cisco's service, with your help I will attempt to write a decoder for it.

Could you send emails (to yourself, or another email address using Cisco—sometimes emails sent from and to the same domain don't get their URLs mangled in the same way) with URLs from the following file, and post the resulting URLs? (These are the same test URLs that I use in https://github.com/cardi/proofpoint-url-decoder/blob/005dc851c90213fdea07c78511bda61f1efe6d94/decode_test.py)

https://github.com/cardi/proofpoint-url-decoder/blob/005dc851c90213fdea07c78511bda61f1efe6d94/tests/urls-plain.txt