Mike Felch Profile picture
Nov 30 5 tweets 2 min read
Want to create great phishing links using an open-redirect on google.com? While they don't last forever, they are a great way to trick unsuspecting victims into clicking a legit looking URL before expiring! gist.github.com/ustayready/3ba… Follow the 🧵for how it works.. Image
It's actually pretty easy to do manually too! When you add comments to a Doc in Google Workspace, Google will swap out the links using a www[.]google[.]com redirect. So all you need to do is..

1) Create a doc
2) Add a comment with your real phishing URL
3) Send phish w/ new link
To use the gist I posted, you need to create an app on Google Cloud, configure the consent screen, enable Google Docs API, and add credentials.
Once you save the creds, create a Python virtual env and pip install -r requirements.txt w/ the google_lure.py file. Running the script will prompt you to authorize the app. Use a burner account and authorize it.
Finally, the script will do the following:

1) Create a temp doc file
2) Create a comment on the doc
3) Extract the Google redirect URL
4) Delete the temp doc file

That's all! Enjoy.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Mike Felch

Mike Felch Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(