kgretzky / evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
BSD 3-Clause "New" or "Revised" License
10.22k stars 1.87k forks source link

Error blacklist option in 3.3 #1034

Open Dazmed707 opened 2 months ago

Dazmed707 commented 2 months ago

I was using version 3.2 with everything set to blacklist:noadd

When updating to version 3.3 with the blacklist:noadd option it still blocks all requests as if it were in blacklits:all

In order to work, I put blacklist:off so that the link loads, but that leaves me vulnerable, any correction for this?

I don't want to go back to 3.2 because it has the bot detection bug.

0xTidalBore commented 2 months ago

Having same issue after update, even with blacklist off....

Dazmed707 commented 2 months ago

I had to downgrade to 3.2 but without the bot detection patch, I'm going to look for that line to modify and compile until 3.3 is fixed

0xTidalBore commented 2 months ago

I realized there was a conflict in proxy hosts in my phishlet with is_landing set to true more than once, fixed it and things worked just fine

Dazmed707 commented 2 months ago

u can send msg in telegram for help me ? @psdt707