Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

How Much Is The Phish? Evolving Defenses Against Evilginx Reverse Proxy Phishing

x33fcon via YouTube

Overview

Learn about reverse proxy phishing attacks and evolving defense mechanisms in this 33-minute conference talk from x33fcon. Explore the inner workings of Evilginx, a tool that has been at the forefront of MFA bypass attacks for the past six years. Discover how these attacks circumvent multi-factor authentication, examine what users experience during an attack, and understand why current web security measures have struggled to counter this threat effectively. Delve into practical defense strategies including JavaScript detections, dynamic code obfuscation, string obfuscation, and the implementation of secret tokens. Follow along with demonstrations and code examples showing basic protection mechanisms, with special attention to Google's approach to making secret tokens unspoofable. Master essential knowledge for defending against sophisticated phishing attacks that continue to pose significant risks to organizational security.

Syllabus

Introduction
About me
About Evilginx
How does it work
What does the user see
How to bypass multifactor authentication
What can be done
The Fishing Domain
JavaScript Detections
How Evilginx Works
Dynamic Code Obfuscation
String Obfuscation
Summary
Secret Tokens
Basic Protection Code
Google
Secret tokens unspoofable
Demo
Recap

Taught by

x33fcon

Reviews

Start your review of How Much Is The Phish? Evolving Defenses Against Evilginx Reverse Proxy Phishing

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.