mirror of
https://github.com/phishingclub/phishingclub.git
synced 2026-10-03 22:16:49 +02:00
11 files changed
+23
-23
No files matched your search
@@ -2893,7 +2893,7 @@ func (m *ProxyHandler) applyReplacementWithVariables(body []byte, replacement se
|
||||
// callers that handle headers (applyCustomResponseHeaderReplacementsWithVariables,
|
||||
// applyCustomResponseHeaderReplacementsWithoutSession, applyEarlyRequestHeaderReplacements)
|
||||
// intercept this engine before reaching here.
|
||||
m.logger.Errorw("header engine used in a non-header rewrite context — use from: request_header or response_header", "sessionID", sessionID, "rule", replacement.Name)
|
||||
m.logger.Errorw("header engine used in a non-header rewrite context, use from: request_header or response_header", "sessionID", sessionID, "rule", replacement.Name)
|
||||
return body
|
||||
default:
|
||||
m.logger.Errorw("unsupported replacement engine", "engine", engine, "sessionID", sessionID)
|
||||
|
||||
@@ -343,7 +343,7 @@ var knownGoErrors = []struct {
|
||||
substr string
|
||||
message string
|
||||
}{
|
||||
{"connection refused", "browser connection refused — is Chrome running?"},
|
||||
{"connection refused", "browser connection refused, is Chrome running?"},
|
||||
{"use of closed network connection", "browser connection closed unexpectedly"},
|
||||
{"i/o timeout", "browser CDP connection timed out"},
|
||||
{"EOF", "browser disconnected unexpectedly"},
|
||||
|
||||
@@ -303,7 +303,7 @@ func (s *MicrosoftDeviceCode) pollTokenEndpoint(entry *model.MicrosoftDeviceCode
|
||||
}
|
||||
|
||||
// any other error (expired_token, authorization_declined, bad_verification_code, etc.) is terminal
|
||||
return nil, false, false, fmt.Errorf("token endpoint error: %s — %s", errResp.Error, errResp.ErrorDescription)
|
||||
return nil, false, false, fmt.Errorf("token endpoint error: %s: %s", errResp.Error, errResp.ErrorDescription)
|
||||
}
|
||||
|
||||
// GetOrCreateDeviceCode returns an existing valid (non-expired, non-captured) device code for the
|
||||
|
||||
@@ -434,7 +434,7 @@ func (s *Scim) Schemas(baseURL string) []ScimSchema {
|
||||
},
|
||||
{
|
||||
Name: "addresses", Type: "complex", MultiValued: true,
|
||||
Description: "addresses for the user — work address maps to city and country fields",
|
||||
Description: "addresses for the user, work address maps to city and country fields",
|
||||
Required: false, CaseExact: false,
|
||||
Mutability: "readWrite", Returned: "default", Uniqueness: "none",
|
||||
SubAttributes: []ScimSchemaAttribute{
|
||||
@@ -447,13 +447,13 @@ func (s *Scim) Schemas(baseURL string) []ScimSchema {
|
||||
},
|
||||
{
|
||||
Name: "active", Type: "boolean", MultiValued: false,
|
||||
Description: "administrative status of the user — false removes them from all groups",
|
||||
Description: "administrative status of the user, false removes them from all groups",
|
||||
Required: false, CaseExact: false,
|
||||
Mutability: "readWrite", Returned: "default", Uniqueness: "none",
|
||||
},
|
||||
{
|
||||
Name: "externalId", Type: "string", MultiValued: false,
|
||||
Description: "identifier from the provisioning client (stored as extraIdentifier — unique per company)",
|
||||
Description: "identifier from the provisioning client (stored as extraIdentifier, unique per company)",
|
||||
Required: false, CaseExact: true,
|
||||
Mutability: "readWrite", Returned: "default", Uniqueness: "server",
|
||||
},
|
||||
@@ -494,7 +494,7 @@ func (s *Scim) Schemas(baseURL string) []ScimSchema {
|
||||
},
|
||||
{
|
||||
Name: "manager", Type: "complex", MultiValued: false,
|
||||
Description: "the user's manager — not stored, accepted and silently ignored",
|
||||
Description: "the user's manager, not stored, accepted and silently ignored",
|
||||
Required: false, CaseExact: false,
|
||||
Mutability: "readWrite", Returned: "default", Uniqueness: "none",
|
||||
SubAttributes: []ScimSchemaAttribute{
|
||||
|
||||
@@ -135,7 +135,7 @@
|
||||
</script>
|
||||
|
||||
{#if visible}
|
||||
<Modal bind:visible headerText="Report Template — {company?.name}" onClose={close}>
|
||||
<Modal bind:visible headerText="Report Template: {company?.name}" onClose={close}>
|
||||
<FormGrid on:submit={onSubmit} {isSubmitting} modalMode="update">
|
||||
<div
|
||||
class="w-80vw col-start-1 col-end-4 row-start-1 py-8 px-6 flex flex-col bg-white dark:bg-gray-800 text-gray-900 dark:text-gray-100 transition-colors duration-200"
|
||||
|
||||
@@ -2517,7 +2517,7 @@
|
||||
</div>
|
||||
{/if}
|
||||
<span class="form-hint"
|
||||
>allowlist of query parameters to keep — if empty, all parameters are
|
||||
>allowlist of query parameters to keep. If empty, all parameters are
|
||||
forwarded</span
|
||||
>
|
||||
</div>
|
||||
@@ -3459,7 +3459,7 @@
|
||||
</div>
|
||||
{/if}
|
||||
<span class="form-hint"
|
||||
>allowlist of query parameters to keep — if empty, all parameters are
|
||||
>allowlist of query parameters to keep. If empty, all parameters are
|
||||
forwarded</span
|
||||
>
|
||||
</div>
|
||||
|
||||
@@ -1340,7 +1340,7 @@ declare var Infinity: number;
|
||||
>
|
||||
<div class="flex flex-col">
|
||||
<p class="font-semibold text-slate-600 dark:text-gray-400 py-2 transition-colors duration-200 text-sm">
|
||||
Flags <span class="font-normal text-xs">(one per line — <code class="font-mono">--flag</code> adds/overrides, <code class="font-mono">!--flag</code> removes)</span>
|
||||
Flags <span class="font-normal text-xs">(one per line, <code class="font-mono">--flag</code> adds/overrides, <code class="font-mono">!--flag</code> removes)</span>
|
||||
</p>
|
||||
<textarea
|
||||
bind:value={cfgExtraFlags}
|
||||
|
||||
@@ -643,7 +643,7 @@ export class ProxyYamlCompletionProvider {
|
||||
kind: this.monaco.languages.CompletionItemKind.Property,
|
||||
insertText: 'action: "set"',
|
||||
documentation:
|
||||
'DOM action: setText, setHtml, setAttr, removeAttr, addClass, removeClass, remove — Header action: set, add, remove',
|
||||
'DOM action: setText, setHtml, setAttr, removeAttr, addClass, removeClass, remove. Header action: set, add, remove',
|
||||
range
|
||||
},
|
||||
{
|
||||
@@ -1092,7 +1092,7 @@ export class ProxyYamlCompletionProvider {
|
||||
label: 'dom',
|
||||
kind: this.monaco.languages.CompletionItemKind.Value,
|
||||
insertText: 'dom',
|
||||
documentation: 'DOM manipulation — modify HTML elements via CSS selectors',
|
||||
documentation: 'DOM manipulation: modify HTML elements via CSS selectors',
|
||||
range
|
||||
}
|
||||
];
|
||||
@@ -1103,7 +1103,7 @@ export class ProxyYamlCompletionProvider {
|
||||
kind: this.monaco.languages.CompletionItemKind.Value,
|
||||
insertText: 'status',
|
||||
documentation:
|
||||
'Diagnostic only — on visiting the rule path, report which required captures have not fired yet. Captures no data and does not affect the flow',
|
||||
'Diagnostic only: on visiting the rule path, report which required captures have not fired yet. Captures no data and does not affect the flow',
|
||||
range
|
||||
}
|
||||
];
|
||||
@@ -1268,7 +1268,7 @@ export class ProxyYamlCompletionProvider {
|
||||
method: 'HTTP method to match (GET, POST, PUT, DELETE, etc.)',
|
||||
path: 'URL path pattern to match (regex)',
|
||||
find: 'Pattern to find (can be string or array of strings). Meaning depends on engine: regex pattern (regex), header name (header), cookie name (cookie), JSON path (json), form field name (form/urlencoded/form-data/multipart), CSS selector (dom)',
|
||||
from: 'Location to search: request_body, request_header, response_body, response_header, any — for capture: cookie also valid (deprecated, use engine instead)',
|
||||
from: 'Location to search: request_body, request_header, response_body, response_header, any. For capture: cookie also valid (deprecated, use engine instead)',
|
||||
required: 'Whether this capture is required for page and capture completion',
|
||||
event:
|
||||
'Event type to save when data is captured: "submit" (default, saved as submitted-data event) or "info" (saved as low-priority info event)',
|
||||
@@ -1281,9 +1281,9 @@ export class ProxyYamlCompletionProvider {
|
||||
replace:
|
||||
'Replacement value: replacement text (regex engine), value for dom actions, or new header value (header engine)',
|
||||
engine:
|
||||
'Engine type - For capture: regex (default), header, cookie, json, form/urlencoded/formdata/multipart. For rewrite: regex (default), dom (HTML manipulation), header (set/add/remove a header directly)',
|
||||
'Engine type. For capture: regex (default), header, cookie, json, form/urlencoded/formdata/multipart. For rewrite: regex (default), dom (HTML manipulation), header (set/add/remove a header directly)',
|
||||
action:
|
||||
'For dom engine: setText, setHtml, setAttr, removeAttr, addClass, removeClass, remove — For header engine: set (overwrite), add (append), remove (delete)',
|
||||
'For dom engine: setText, setHtml, setAttr, removeAttr, addClass, removeClass, remove. For header engine: set (overwrite), add (append), remove (delete)',
|
||||
target:
|
||||
'Target matching (dom engine only): "first", "last", "all" (default), "1,3,5" (specific), "2-4" (range)',
|
||||
to: 'Target phishing domain for this original domain',
|
||||
|
||||
@@ -306,7 +306,7 @@ s.keepAlive();
|
||||
To enable it, set <code class="text-slate-200 bg-slate-700 px-1 rounded">enabled: true</code
|
||||
>
|
||||
in the <code class="text-slate-200 bg-slate-700 px-1 rounded">remote_browser</code> block of
|
||||
<code class="text-slate-200 bg-slate-700 px-1 rounded">config.json</code> and retart the service.
|
||||
<code class="text-slate-200 bg-slate-700 px-1 rounded">config.json</code> and restart the service.
|
||||
</p>
|
||||
<a
|
||||
href="https://phishing.club/guide/remote-browser/#enabling"
|
||||
|
||||
@@ -274,7 +274,7 @@
|
||||
<p class="mb-1 text-sm font-semibold text-white">Scripts are not enabled</p>
|
||||
<p class="mb-3 text-sm text-slate-400">
|
||||
This feature is disabled by default for security reasons. When enabled, any operator with
|
||||
access can write scripts that run on the server when campaign events fire — including
|
||||
access can write scripts that run on the server when campaign events fire, including
|
||||
making outbound HTTP requests. Only enable it on instances where every operator is trusted
|
||||
as a server admin.
|
||||
</p>
|
||||
|
||||
@@ -429,7 +429,7 @@
|
||||
{#each importResult.assets_errors_list as err}
|
||||
<li>
|
||||
<strong>{err.type}:</strong>
|
||||
{err.name} — {err.message}
|
||||
{err.name}: {err.message}
|
||||
</li>
|
||||
{/each}
|
||||
</ul>
|
||||
@@ -477,7 +477,7 @@
|
||||
{#each importResult.pages_errors_list as err}
|
||||
<li>
|
||||
<strong>{err.type}:</strong>
|
||||
{err.name} — {err.message}
|
||||
{err.name}: {err.message}
|
||||
</li>
|
||||
{/each}
|
||||
</ul>
|
||||
@@ -518,7 +518,7 @@
|
||||
{#each importResult.emails_errors_list as err}
|
||||
<li>
|
||||
<strong>{err.type}:</strong>
|
||||
{err.name} — {err.message}
|
||||
{err.name}: {err.message}
|
||||
</li>
|
||||
{/each}
|
||||
</ul>
|
||||
@@ -537,7 +537,7 @@
|
||||
{#each importResult.errors as err}
|
||||
<li>
|
||||
<strong>{err.type}:</strong>
|
||||
{err.name} — {err.message}
|
||||
{err.name}: {err.message}
|
||||
</li>
|
||||
{/each}
|
||||
</ul>
|
||||
|
||||
Reference in new issue
Block a user