• 2 Posts
  • 59 Comments
Joined 3 years ago
cake
Cake day: June 30th, 2023

help-circle





  • The attacker could brute force it. Or they can make a phishing page to try and get the user to enter in their password.

    1. An attacker would get a similar enough looking domain and mimic the target login page using something like EvilNginx
    2. The attacker would send a fake email to the victim while looking as legit as possible. Saying something like too many login attempts have been detected, please use this URL to confirm your account, or your password is expiring please use this URL to update it. That sort of thing.
    3. The victim would click the URL going to the attackers login page and enter in their details.
    4. The attacker now has the valid login credentials.