v3.2.0
run-llama/liteparsev3.2.0Aug 24, 2023by kgretzky
AI Summary
Focuses on dynamic phishing interactions, including real-time URL redirection, pause functionality, and HTTP request interception for phishlets.
Key Highlights
- Dynamic URL redirects on phishing pages that work without page reloads.
- New `lures pause` command allows pausing lures for fixed durations.
- Phishlets can now intercept HTTP requests and return custom responses.
- Configuration updates including `unauth_url` and removal of `ua_filter` column.
Breaking Changes
- Renamed `redirect_url` to `unauth_url` in global config.
- Removed `ua_filter` column from the lures list view (still viewable in detailed view).
New Features
- Dynamic URL redirects on successful token capture.
- Pause functionality for lures.
- Phishlet HTTP request interception capabilities.
- Global override for unauthorized redirect URLs per phishlet.
Full Release Notes
- Feature: URL redirects on successful token capture now work dynamically on every phishing page. Pages do not need to reload or redirect first for the redirects to happen. - Feature: Lures can now be paused for a fixed time duration with `lures pause <id>`. Useful when you want to briefly redirect your lure URL when you know sandboxes will try to scan them. - Feature: Added phishlet ability to intercept HTTP requests and return custom responses via a new `intercept` section. - Feature: Added a new optional `redirect_url` value for phishlet config, which can hold a default redirect URL, to redirect to, once tokens are successfully captured. `redirect_url` set for the specific lure will override this value. - Feature: You can now override globally set unauthorized redirect URL per phishlet with `phishlet unauth_url <phishlet> <url>`. - Fixed: Disabled caching for HTML and Javascript content to make on-the-fly proxied content replacements and injections more reliable. - Fixed: Improved JS injection by adding `<script src"...">` references into HTML pages, instead of dumping the whole script there. - Fixed: Blocked requests will now redirect using javascript, instead of HTTP location header. - Fixed: Changed `redirect_url` to `unauth_url` in global config to avoid confusion. - Fixed: Fixed HTTP status code response for Javascript redirects. - Fixed: Javascript redirects now happen on `text/html` pages with valid HTML content. - Fixed: Removed `ua_filter` column from the lures list view. It is still viewable in lure detailed view.