1. Kuba Gretzky: Keynote: A Smooth Sea Never Made a Skilled Phisherman

  Рет қаралды 2,471

x33fcon

x33fcon

Күн бұрын

With the increase in reverse proxy phishing attacks worldwide, major vendors have started implementing more advanced detections. Is it enough to prevent the most determined attackers? I will take you on a deep dive into bypassing the most modern anti-phishing protections with Evilginx Pro.
First, KG will explain what the major vendors are doing to protect their users from reverse proxy phishing, including techniques like:
JA3/JA4 fingerprinting.
Using "Shadow token" or "secret token" smuggling.
Telemetry gathering through obfuscated JavaScript.
After presenting how the protections work he will jump into the demo of Evilginx Pro, showing how it differs from the public version of Evilginx. He will show how red teams can maximize their effectiveness using the new UI improvements and anti-detection measures. He will also try to briefly demonstrate Evilpuppet - the module of Evilginx Pro, which allows Evilginx to interface with the background browser to extract tokens and other data from legitimate sign-in sessions.
He will conclude with the demonstration of Evilginx Pro in action, performing a successful phishing attack on a well-protected target.

Пікірлер
What's new in the world of reverse proxy phishing?
1:22:03
Off By One Security
Рет қаралды 3,1 М.
Running With Bigger And Bigger Feastables
00:17
MrBeast
Рет қаралды 170 МЛН
What will he say ? 😱 #smarthome #cleaning #homecleaning #gadgets
01:00
ROLLING DOWN
00:20
Natan por Aí
Рет қаралды 11 МЛН
DASH 2024 Keynote
1:42:28
Datadog
Рет қаралды 9 М.
Phishing 2.0 - Detecting Evilginx, EvilnoVNC, Muraena and Modlishka
46:05
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 1,6 МЛН
Insane Vulnerability In OpenSSH Discovered
1:06:56
ThePrimeTime
Рет қаралды 173 М.
How A Printer Lost A Country $81,000,000
15:58
Cipher
Рет қаралды 534 М.
Solving a REAL investigation using OSINT
19:03
Gary Ruddell
Рет қаралды 160 М.
"The Life & Death of htmx" by Alexander Petros at Big Sky Dev Con 2024
23:01
Montana Programmers
Рет қаралды 54 М.
Proxy vs Reverse Proxy Explained
8:05
PowerCert Animated Videos
Рет қаралды 363 М.
MALWARE ANALYSIS // How to get started with John Hammond
55:45
David Bombal
Рет қаралды 291 М.