cmlh / Maltego-haveibeenpwned

Maltego integration of https://haveibeenpwned.com
GNU General Public License v2.0
58 stars 15 forks source link

Support `hibp-api-key` Transform Setting #30

Open cmlh opened 4 years ago

cmlh commented 4 years ago

Available to Maltego Classic and [Maltego] XL are:

Therefore, Maltego CE will be limited to

Refer to @troyhunt Blog Post for further information

jl-dos commented 4 years ago

Is this something you are willing to add in as a supported input to the plugin? Looks like the ability to query has ended in the last little bit as the requests previously worked about 2-3 weeks ago but throw API errors as of this week for breaches by account. Using api key direct works as expected in a raw http request.

cmlh commented 4 years ago

@jl-dos

Is this something you are willing to add in as a supported input to the plugin? Looks like the ability to query has ended in the last little bit as the requests previously worked about 2-3 weeks ago but throw API errors as of this week for breaches by account. Using api key direct works as expected in a raw http request.

The code to support #30 has already shipped but I'll need to activate it once https://www.troyhunt.com/project-svalbard-the-future-of-have-i-been-pwned/ is sold.

Can you send me a screenshot of your error please?

jl-dos commented 4 years ago

Screenshot attached. Screen Shot 2019-11-04 at 9 58 50 AM

pb00001 commented 4 years ago

Exactly same error here.

andrewblack753 commented 4 years ago

Same error for me

cmlh commented 4 years ago

@jl-dos @pbuen0 @andrewblack753

The API Key is still valid for the next ~20 days i.e. until 5:19 GMT on 26 November 2019

image

I would suspect the issue may be similar to the upstream issue within Azure in late August as documented within https://twitter.com/troyhunt/status/1164291579705610240 and I am working with @troyhunt on a resolution.

cmlh commented 4 years ago

@jl-dos @pbuen0 @andrewblack753 @Fiebererdi

This has been resolved.

jl-dos commented 4 years ago

@jl-dos

Is this something you are willing to add in as a supported input to the plugin? Looks like the ability to query has ended in the last little bit as the requests previously worked about 2-3 weeks ago but throw API errors as of this week for breaches by account. Using api key direct works as expected in a raw http request.

The code to support #30 has already shipped but I'll need to activate it once https://www.troyhunt.com/project-svalbard-the-future-of-have-i-been-pwned/ is sold.

Can you send me a screenshot of your error please?

Confirmed queries are working again. Will the feature to support our own api keys with a parameter still be added in the future? Thank you

cmlh commented 4 years ago

@jl-dos

Support for this Transform Setting has already been developed I just haven't turned it on yet due to the upstream issue[s] such as https://twitter.com/troyhunt/status/1164291579705610240

Once these issue[s] are settled, which I forecast will be sometime after the sale of "Have I Been Pwned?", then I will activate this Transform Setting.

troyhunt commented 4 years ago

This is incorrect on multiple levels:

The tweet you linked to is at the head of a thread which shows the issue being resolved all the way back in August: https://twitter.com/troyhunt/status/1167604726944296960

And it's entirely unrelated to the sale of HIBP as it's been resolved for months now.

cmlh commented 4 years ago

@troyhunt

The tweet you linked to is at the head of a thread which shows the issue being resolved all the way back in August: https://twitter.com/troyhunt/status/1167604726944296960

The API Key was automatically renewed on 26 October but began to fail from 1 November. I sent you an e-mail on 6 November but never received a reply.

And it's entirely unrelated to the sale of HIBP as it's been resolved for months now.

How I will price my integration with Maltego is dependent on your sale.

cmlh commented 10 months ago

@jl-dos @pbuen0 @andrewblack753 @Fiebererdi,

I'll reconsider this once #35 is closed as #35 has a direct dependency on the @HaveIBeenPwned API Key.