fkasler/phishmonger

O365 removing first two digits of Phishmonger reference

Closed this issue · 1 comments

This is more an observation, this is not a problem with Phishmonger I don't think:
Testing today with two different mailboxes - the supplied link has the first two digits removed after the id parameter name - example:

image

Link in email is this:
https://myphishinglink/?id1=epxi

Is this some new protection - or anything you have seen before?

I have tried changing the id generation to 4 characters from 6 and the same thing happens, the first two characters are removed from the link in the email?

This is preventing the tracking and capturing of data.

I don't know if this is a result of a crappy CSS entry or something in the source email I am using, but I have worked around this by adding a prefix of two characters to the target_id. This gets removed leaving the full target_id in the link.