Mike Felch (Stay Ready) Profile picture
Pentester / Red Team | Hacking since Renegade BBS backdoors | Dev since vb3 | Content since '99-'03 ezines | Prior CrowdStrike / BHIS | In Christ's grip
Nov 30, 2022 5 tweets 2 min read
Want to create great phishing links using an open-redirect on google.com? While they don't last forever, they are a great way to trick unsuspecting victims into clicking a legit looking URL before expiring! gist.github.com/ustayready/3ba… Follow the 🧵for how it works.. Image It's actually pretty easy to do manually too! When you add comments to a Doc in Google Workspace, Google will swap out the links using a www[.]google[.]com redirect. So all you need to do is..

1) Create a doc
2) Add a comment with your real phishing URL
3) Send phish w/ new link