optiv / Go365

An Office365 User Attack Tool
MIT License
621 stars 100 forks source link

AWS API #4

Open jc1396 opened 3 years ago

jc1396 commented 3 years ago

When using the ASW API option, everything is responding as a valid account?

pavetheway commented 3 years ago

are you using the AWS gateway link in the readme?

PocketDC commented 3 years ago

having the same issue; could just be an idiot but tried setting up the AWS API integration and pointing the tool at it and getting all valid results.

Are there specific settings recommended for API Gateway?

pavetheway commented 3 years ago

https://bigb0ss.medium.com/rotating-source-ips-part-1-aws-api-gateway-fe29d2c5e008

Try using the instructions in this blog post to set up the AWS gateway then LMK what the results are.

ghost commented 1 year ago

-debug shows the following Debug: {"message":"Missing Authentication Token"} when run without gateway -url the AADSTS codes come back in response

KyanHexagon commented 1 year ago

Is there a fix or workaround for this?