How to Bypass MFA - A Real Time Example (It's easy)

  Рет қаралды 3,902

CloudGuard AI

CloudGuard AI

Күн бұрын

Пікірлер: 8
@caraher
@caraher 3 ай бұрын
Nice demonstration, good topic
@CloudGuardAI
@CloudGuardAI 3 ай бұрын
Glad you liked it!
@LelioCosta
@LelioCosta 3 ай бұрын
Tanks for sharing this
@CloudGuardAI
@CloudGuardAI 3 ай бұрын
no problem! more to come!
@Grunfeld
@Grunfeld 4 ай бұрын
Thanks for the video. At work I authenticate my login to their Microsoft software using a number generated by my Yubikey and my phone. This feels the same level as in your Alice scenario. At home I physically insert the key into my laptop; this feels more like your Bob scenario. Have I understood that right?
@CloudGuardAI
@CloudGuardAI 4 ай бұрын
So essentially you're using the Yubikey app on your phone to generate OTPs (one-time passcodes), and is similar to the OTP numbers you get generated in the Microsoft Authenticator app, or any other common authentication applications such as Google Authenticator or Authy. The weakness with OTP is that there's no built-in checks performed with this method of MFA to validate the target domain you're entering your credentials into is legitimate. One thing to bear in mind is that if you're using the Yubikey application on your laptop to generate OTPs you will still be asked to insert your Yubikey to access and unlock the key, however it's not using WebAuthn or FIDO2. If you currently use the cycling codes in the Yubico Authenticator app on your laptop to log in with, then it won't be using FIDO2, meaning it's unfortunately still subject to the AiTM attack as you saw in Alice's scenario. Microsoft supports FIDO2 with Yubikeys so you would just need to register your Yubikey as a FIDO2 device and add this as your preferred method of authentication. Depending on your or your workplace setup, they may not allow this by default, so you would need to ask them to enable FIDO2 authentication for you, and you can then register it. We hope that helps!
@Grunfeld
@Grunfeld 4 ай бұрын
​@@CloudGuardAI Thank you for the reply and the suggestion to enable FIDO2. I shall learn how to do this (lol, I'll likely end up looking on KZbin!) 🙂
@CloudGuardAI
@CloudGuardAI 4 ай бұрын
We've taken your feedback on board and hope to make a video on it soon. :)
Phishing Resistant MFA How it Works!
15:26
Andy Malone MVP
Рет қаралды 13 М.
How to Find MFA Bypasses in Conditional Access Policies
12:46
Beau Bullock
Рет қаралды 33 М.
Officer Rabbit is so bad. He made Luffy deaf. #funny #supersiblings #comedy
00:18
Funny superhero siblings
Рет қаралды 7 МЛН
OYUNCAK MİKROFON İLE TRAFİK LAMBASINI DEĞİŞTİRDİ 😱
00:17
Melih Taşçı
Рет қаралды 12 МЛН
Minecraft Creeper Family is back! #minecraft #funny #memes
00:26
How hackers are breaking into MFA enabled Microsoft 365 accounts
6:00
4 CRITICAL Places to Use a YubiKey (beyond an email account)
13:08
All Things Secured
Рет қаралды 96 М.
Malware beats Windows Defender: How you get hacked
7:26
The PC Security Channel
Рет қаралды 192 М.
Lock Down Your Microsoft 365: Your Essential Security Policies
22:09
Jonathan Edwards
Рет қаралды 42 М.
Stewie as a teenager
10:03
Hear Me Roar
Рет қаралды 2,9 МЛН
How Security Keys work (2FA explained!)
17:42
Naomi Brockwell TV
Рет қаралды 151 М.
The Easiest (and MOST SECURE) Way to Log into Bitwarden
9:00
Jason Rebholz - TeachMeCyber
Рет қаралды 32 М.
Officer Rabbit is so bad. He made Luffy deaf. #funny #supersiblings #comedy
00:18
Funny superhero siblings
Рет қаралды 7 МЛН