Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

🚨 Evilginx Pro release is coming soon 🔥 I've just finished rewriting Evilpuppet to prepare it for release. Here is a demo of how it allows red teams to bypass Google's modern anti-phishing protections. 🪝🐟 ⏰ Get 20% OFF Evilginx Mastery course:

43,841 Aufrufe • vor 2 Jahren •via X (Twitter)

10 Kommentare

Profilbild von mr.d0x
mr.d0xvor 2 Jahren

🔥🔥

Profilbild von Pentest List
Pentest Listvor 2 Jahren

🔥

Profilbild von Kuba Gretzky
Kuba Gretzkyvor 2 Jahren

Me too 😂 Would be great to drop it already!

Profilbild von Neil
Neilvor 2 Jahren

Man i couldnt quite build that during my last engagement. Considered just doing a single phish at a time, will be nice to just pay and have it all ready to go.

Profilbild von Kuba Gretzky
Kuba Gretzkyvor 2 Jahren

I am working on making it as plug-and-play as possible 🙂

Profilbild von DheReckahCoded
DheReckahCodedvor 1 Jahr

Good Job 👍🏽 @mrgretzky I hope the big tech like Google aren’t worried because am also coming up with something, your tool is always sample to each of anyone of us whose intent is to deeply look into the advance 2fa bypass

Profilbild von ragey🎗️
ragey🎗️vor 2 Jahren

you are one badass dude

Profilbild von Amin
Aminvor 1 Jahr

Cant wait to have it available

Profilbild von Ach Raf
Ach Rafvor 2 Jahren

When you will open the registration for the pro version? I am waiting for months now 🥲

Profilbild von Kuba Gretzky
Kuba Gretzkyvor 2 Jahren

Today 🙂

Ähnliche Videos

Is reverse proxy phishing slowly dying? 💀🎣 This is what I've been trying to find out during the past several months. Major websites have caught up and vastly improved their security, successfully detecting malicious traffic originating from reverse-proxy phishing servers. The attackers have changed their tactics and begun utilising a new method that involves using a real web browser to sign in on the phished user's behalf. In the video I've just released, I am demonstrating a live demo of a modern phishing attack using the Credential Relay Phishing technique, which evades all current anti-phishing measures deployed against reverse-proxy phishing. To simulate a phishing attack against a Google account secured with FIDO MFA, I am using the latest features of Evilginx Pro to downgrade the FIDO MFA to less secure & phishable MFA alternatives. Additionally, the attack simulation employs a Browser-in-the-Browser social engineering technique to spoof the phishing URL in the address bar of the fake pop-up window, displaying the sign-in page. Everything you see in the video is ready to use in the latest beta version of Evilginx Pro, available exclusively to vetted cybersecurity professionals working within cybersecurity companies or internal red teams. Evilginx Pro's latest features include: Phishlets 2.0: A complete rewrite of the old phishlets format now allows for modification of every part of HTTP traffic going through the reverse proxy server. The new format allows hosting of static website content utilising external modules such as Evilpuppet to simulate Credential Relay Phishing attacks. Downgrading FIDO MFA: With the most recent implementation of Evilpuppet, it is now possible to control a separate background browser session and sign in on behalf of the phished user, allowing the attacker to be the one responsible for choosing which MFA method the user should authenticate with. Browser-in-the-Browser: It is now possible to embed any phishing page within a fake browser pop-up window, rendered with JavaScript and stylised for the OS on which the page is displayed. This enables the construction of extremely convincing social engineering attacks, as the URL in the pop-up window can be spoofed to any value using legitimate hostnames. If you want to use these features in your next red team engagement or assess your company's readiness against modern phishing attacks, make sure to give Evilginx Pro a try. Hope you enjoy the video! 💗 Happy phishing! 🪝🐟 Kuba

Kuba Gretzky

24,829 Aufrufe • vor 12 Tagen