Skip to content

Update msol.py to prevent false negatives when spraying#56

Open
absolomb wants to merge 1 commit into
blacklanternsecurity:trevorspray-v2from
absolomb:trevorspray-v2
Open

Update msol.py to prevent false negatives when spraying#56
absolomb wants to merge 1 commit into
blacklanternsecurity:trevorspray-v2from
absolomb:trevorspray-v2

Conversation

@absolomb

@absolomb absolomb commented Jul 9, 2026

Copy link
Copy Markdown

The current client id when spraying using the msol module will throw "Got an error we haven't seen yet" due to the client id no longer being supported by graph.windows.net resource when valid creds are sprayed, and will subsequently not display the creds as valid due to hitting this error. I've updated the client id to match the one for Microsoft Office and target graph.microsoft.com instead going forward, since eventually the old Graph API will eventually be decommissioned and there will probably be more issues targeting it. I also added error handling for two more relevant errors in case this happens in the future.

@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@absolomb

absolomb commented Jul 9, 2026

Copy link
Copy Markdown
Author

I have read the CLA Document and I hereby sign the CLA

bls-cla-bot Bot added a commit to blacklanternsecurity/CLA that referenced this pull request Jul 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant