要查看 KnockKnock 的最新版本或提交问题,请参考 https://github.com/waffl3ss/KnockKnock。
设计用于通过查询 OneDrive 和/或 Microsoft Teams 来验证潜在用户名,这些是被动方法。
它可以输出/创建通过 Microsoft Teams 枚举识别出的旧版 Skype 用户列表。
它还可以从 Teams 获取详细信息,例如可用性、设备类型和外出留言。
最后,它还能生成一份整洁的列表供将来使用,所有操作均通过单一工具完成。
$ python3 .\KnockKnock.py -h
_ __ _ _ __ _
| |/ /_ __ ___ ___| | _| |/ /_ __ ___ ___| | __
| ' /| '_ \ / _ \ / __| |/ / ' /| '_ \ / _ \ / __| |/ /
| . \| | | | (_) | (__| <| . \| | | | (_) | (__| <
|_|\_\_| |_|\___/ \___|_|\_\_|\_\_| |_|\___/ \___|_|\_\
v0.9.9 @waffl3ss
usage: KnockKnock.py [-h] [-teams] [-onedrive] [-l] -i INPUTLIST [-o OUTPUTFILE] -d TARGETDOMAIN [-t TEAMSTOKEN] [-threads MAXTHREADS] [-v]
options:
-h, --help show this help message and exit
-teams Run the Teams User Enumeration Module
-onedrive Run the One Drive Enumeration Module
-l Write legacy skype users to a seperate file
-s Write Teams Status for users to a seperate file
-i INPUTLIST Input file with newline-seperated users to check
-o OUTPUTFILE Write output to file
-d TARGETDOMAIN Domain to target
-t TEAMSTOKEN Teams Token (file containing token or a string)
-threads MAXTHREADS Number of threads to use in the Teams User Enumeration (default = 10)
-v Show verbose errors
./KnockKnock.py -teams -i UsersList.txt -d Example.com -o OutFile.txt -t BearerToken.txt
./KnockKnock.py -onedrive -i UsersList.txt -d Example.com -o OutFile.txt
./KnockKnock.py -onedrive -teams -i UsersList.txt -d Example.com -t BearerToken.txt -l
要获取你的 Bearer 令牌,你需要在浏览器中安装 Cookie 管理器插件,并通过浏览器登录你自己的 Microsoft Teams。
接下来,查看与当前网页(teams.microsoft.com)相关的 Cookies。
你要找的 Cookie 对应于域 .teams.microsoft.com,名称为 'authtoken'。
你可以复制整个令牌,因为脚本会为你提取所需的部分。