#Evilginx

these machines will destroy US.cienmilojos@infosec.exchange
2025-02-18

So #evilginx is a MITM attack that is used to steal login credentials and highjack the session cookie. How can this be mitigated outside of providing users with a physical token? #MFA #MITM #FIDO2

hackmachackmac
2024-09-17

Die Einrichtung der MFA halte ich weiterhin für wichtig, um das Risiko der Account-Übernahme zu reduzieren, auch wenn es inzwischen Tools wie Evilginx gibt, die den zweiten Faktor "umgehen".

zac-niedersachsen.de/artikel/80

2024-07-14

Life has felt a bit less hectic these last few months and I feel at peace with some things I won’t go into. With that, I’ve been able to restructure what I want to focus on with a more narrow scope without my mind feeling as chaotic.
Some things I’m starting / want to start soon:
Read the Psychology of Intelligence Analysis
Revisit learning #Go mainly for HTTP utilities
Learn #Evilginx and #GoPhish (apply Golang knowledge here) to get a deeper understanding of #phishing threats on both offensive and defensive side.
Read more in general— this #cti paper was very insightful tandfonline.com/doi/full/10.10

This still appears to be somewhat broad scoped but it helps build a structure.

2024-06-28

In this article I describe a potential attack against many Webauthn (i.e. passkeys or hardware security keys) implementations, that I'm calling an Authentication Method Redaction (AMR) attack.

esentire.com/blog/securing-pas

#passkeys #webauthn #authentication #evilginx #phishing #mfa

Christophe Romexof@social.annacon.be
2024-06-13

Happy to see Kuba Gretzky kicking it off with one of my favorite topics and what can indeed be labeled as one of the biggest elephants in the cybersecurity community's room. How to prevent bad guys from using red teaming tools?

For sure there are no easy cures but we should at least acknowledge the issue and work towards solutions.

#x33fcon #evilginx #cybersecurity

Aloïs Thévenot :verified:techbrunchfr@infosec.exchange
2024-06-10

Phishing Like a Pro: A Guide for Pentesters to Add SPF, DMARC, DKIM and MX records to Evilginx - fortbridge.co.uk/research/add- #phishing #evilginx

Slim Bill (He/Him)wjmalik@noc.social
2024-01-30

A Bit of Security for Jan 30, 2024
How can you prove you are who you say you are when you’re talking to a computer? Listen to this -
youtu.be/HBHs191WD08
Let me know what you think at wjmailk@noc.social

#cybersecuritytips #evilginx #MFA #phishing #BitofSec

Milos ConstantinTinolle@hachyderm.io
2024-01-27

A new approach to Browser In The Browser (#BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login pages like #Microsoft and the use with #Evilginx. : github.com/waelmas/frameless-b

2024-01-16

is #evilginx still a thing to phish outlook.com credentials / token? #evilginx2

Tedi Heriyantotedi@infosec.exchange
2023-12-15

Great post about current #Microsoft #Azure / #M365 attack tooling including #evilginx and #roadtools.

The posting also describes the automation from capturing tokens to exfiltrate data - good luck defenders when not automating the defense …

trustedsec.com/blog/the-trifor

Merill Fernando :verified: :donor:merill@infosec.exchange
2023-11-11

Kuba @mrgretzky is building an awesome community around Evilginx at Breakdev Red.

I 😍 the hilarious response I received for my whoami post 😂

#evilginx #community #entraid

Comment: Behind enemy lines

Nice to see you here Merill
☄️ jskhermanjskherman@mathstodon.xyz
2023-11-02

It's crazy how even multi-factor authentication can be bypassed by stealing the Auth Cookie for a session with #evilginx. Being more vigilant of domain names is a must nowadays, especially when landing pages can be made nearly similar to the official pages from sites you visit.

I have mixed feelings about #evilginx being #OpenSource. On one hand, it's good that it's open source and knowledge of such #exploit methods is thoroughly known, but on the other hand it also makes it easier for more people to have a chance at doing sophisticated #phishing attacks by presenting it as an easy to install binary with an accompanying course on how to set up the configs properly.

youtu.be/sZ22YulJwao
github.com/kgretzky/evilginx2

2023-09-04

Looking at the Github issues on #evilginx, the progressive changes to `ISSUE_TEMPLATE.md` and how the vast majority of issues still fully ignore it, has convinced me that I never, ever want any red-team tool I ever write to reach any kind of notoriety or visibility in the public consciousness.

I think the inclusion of any tool I write into a release of #Kali would probably have me remove the damn thing from github 🙃

I feel for the author 🫠

github.com/kgretzky/evilginx2

Eric Woodruff [MS MVP] :donor:ericonidentity@infosec.exchange
2023-08-27

For anyone at @BlueTeamCon who wants to understand why many forms of MFA are not phishing-resistant and why passkeys/FIDO2 are, tomorrow at 12:20pm during lunch in the #unconference room I’ll be delivering an impromptu session on #phishing resistant authentication, including a live demo of #evilginx.

#BlueTeamCon #BlueTeam #blueteamcon2023 #mvpbuzz #infosec

Aloïs Thévenot :verified:techbrunchfr@infosec.exchange
2023-08-24

How Much Is The Phish? Evolving Defences Against Evilginx Reverse Proxy - youtube.com/watch?v=C-Fh4sIdY8 #phishing #evilginx

Aloïs Thévenot :verified:techbrunchfr@infosec.exchange
2023-08-03

Hook, Line, and Phishlet: Conquering AD FS with Evilginx - research.aurainfosec.io/pentes #phishing #evilginx

Who Let The Dogs Out 🐾ashed@mastodon.ml
2021-08-27

sidb.in/2021/08/03/Phishing-0-
The Ultimate Guide to Phishing
Learn how to Phish using EvilGinx2 and GoPhish
Posted by Siddharth Balyan on August 03, 2021 · 15 mins read

#phishing #evilginx #guide

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst