Hacker News
- Evilginx2: Standalone man-in-the-middle attack framework https://github.com/kgretzky/evilginx2 7 comments
Linking pages
- From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud - Microsoft Security Blog https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/ 20 comments
- Encryption at Rest has become a buzzword. — Blog — Evervault https://evervault.com/blog/is-encryption-at-rest-a-scam 14 comments
- Steal Credentials & Bypass 2FA Using noVNC | mr.d0x https://mrd0x.com/bypass-2fa-using-novnc/ 13 comments
- Phishing Users with MFA on AWS - Rhino Security Labs https://rhinosecuritylabs.com/aws/mfa-phishing-on-aws/ 9 comments
- Add SPF, DMARC, DKIM and MX Records to Evilginx - Cyber Security Services - London https://fortbridge.co.uk/research/add-spf-dmarc-dkim-mx-records-evilginx/ 9 comments
- GitHub - Z4nzu/hackingtool: ALL IN ONE Hacking Tool For Hackers https://github.com/Z4nzu/hackingtool 6 comments
- When Certificates Fail: A Story of Bypassed MFA in Remote Access - https://edermi.github.io/post/2024/mfa_bypass_mtls/ 6 comments
- Rivers of Phish: Sophisticated Phishing Targets Russia’s Perceived Enemies Around the Globe - The Citizen Lab https://citizenlab.ca/2024/08/sophisticated-phishing-targets-russias-perceived-enemies-around-the-globe/ 3 comments
- Office 365 phishing campaign that can bypass MFA targets 10,000 organizations | CSO Online https://www.csoonline.com/article/3666697/office-365-phishing-campaign-that-can-bypass-mfa-targets-10-000-organizations.html 2 comments
- GitHub - thehappydinoa/awesome-censys-queries: A collection of fascinating and bizarre Censys Search Queries https://github.com/thehappydinoa/awesome-censys-queries 1 comment
- Bypassing LastPass’s “Advanced” YubiKey MFA: A MITM Phishing Attack https://pberba.github.io/security/2020/05/28/lastpass-phishing/ 1 comment
- GitHub - infosecn1nja/Red-Teaming-Toolkit: This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter. https://github.com/infosecn1nja/Red-Teaming-Toolkit 1 comment
- Multi-factor Authentication In-The-Wild bypass methods | by Yuval Fischer | ProferoSec | Medium https://medium.com/proferosec-osm/multi-factor-authentication-in-the-wild-bypass-methods-689f53f0b62b 0 comments
- GitHub - fin3ss3g0d/evilgophish: evilginx2 + gophish https://github.com/fin3ss3g0d/evilgophish 0 comments
- U2F with Duo Web Phishable by default https://pberba.github.io/security/2020/06/12/duo-u2f-phising/ 0 comments
- GitHub - may215/awesome-termux-hacking: ⚡️An awesome list of the best Termux hacking tools https://github.com/may215/awesome-termux-hacking 0 comments
- GitHub - enaqx/awesome-pentest: A collection of awesome penetration testing resources, tools and other shiny things https://github.com/enaqx/awesome-pentest 0 comments
- Stealing 2FA Tokens on Red Teams with CredSniper - Black Hills Information Security https://www.blackhillsinfosec.com/stealing-2fa-tokens-on-red-teams-with-credsniper/ 0 comments
- GitHub - Spacial/awesome-csirt: Awesome CSIRT is an curated list of links and resources in security and CSIRT daily activities. https://github.com/Spacial/csirt 0 comments
- Go BLUE! A Protection Plan for Credentials in Chromium-based Browsers https://www.cyberark.com/resources/threat-research-blog/go-blue-a-protection-plan-for-credentials-in-chromium-based-browsers 0 comments
Linked pages
- Evilginx 2 - Next Generation of Phishing 2FA Tokens https://breakdev.org/evilginx-2-next-generation-of-phishing-2fa-tokens/ 36 comments
- Evilginx 2.3 - Phisherman's Dream https://breakdev.org/evilginx-2-3-phishermans-dream/ 4 comments
- Evilginx 2.2 - Jolly Winter Update https://breakdev.org/evilginx-2-2-jolly-winter-update/ 4 comments
- Download and install - The Go Programming Language https://golang.org/doc/install 3 comments