Hacking Two Factor Authentication: Four Methods for Bypassing 2FA and MFA

Поділитися
Вставка
  • Опубліковано 28 чер 2024
  • Bypassing multi-factor authentication was once considered more of a proof of concept then an actual threat. In this video, we will review four common techniques an attacker will utilize to hack multi-factor and two-factor authentication. We’ll review Evilgenix2, which is a popular framework for stealing authentication cookies, and other methods that an attacker can utilize to bypass the authentication process.
    1:06 Evilgenix2 Framework
    2:51 Evilgenix Defense and Protection
    3:45 Pass the Cookie
    5:10 Pass the Cookie Defense and Protection
    5:56 SMS Man-in-the-Middle
    6:34 SIM Swap
    8:13 Attack on Soft and Hard Tokens
    9:22 Hard Token Example
    Resources/Links
    -Evilgenix GitHub: github.com/kgretzky/evilginx2
    -Pass the Cookie example: stealthbits.com/blog/bypassin...
    -Android 0-day SMS: stealthbits.com/blog/bypassin...
  • Наука та технологія

КОМЕНТАРІ • 67

  • @meliois3910
    @meliois3910 2 роки тому +6

    Excellent breakdown. Thank you!!

    • @dorahill
      @dorahill Рік тому

      Hello Looking for help to recover your 2FA, suspended hacked/disabled account back, PRESTINCODDING is the tech guy for the job. He helped me in retrieving both of my account back, after so many trials. I can now log into my account and save my middle school pictures.PRESTINCODDING
      Has 11k+ followers ok create a new account, and message him for help..

  • @josecaro6100
    @josecaro6100 2 роки тому +7

    Recently stumbled upon your Channel and love the concepts ! Keep up the great work!

    • @TheCISOPerspective
      @TheCISOPerspective  2 роки тому

      So happy to hear that! Appreciate the support.

    • @josecaro6100
      @josecaro6100 2 роки тому

      @@TheCISOPerspective I’ve recently broken into information security side of things and just got my first job lined up. Your videos have definitely helped me nail down some of the more complex things. Do you have a discord server or anything along those lines for a community to share insight and news ?

    • @TheCISOPerspective
      @TheCISOPerspective  2 роки тому +1

      @@josecaro6100 No but that's a great idea. I'll look into this and let you know. Thanks for the suggestion

  • @vasiovasio
    @vasiovasio 2 місяці тому +1

    Very Good Overview! Thank you!

  • @khoapham1821
    @khoapham1821 2 роки тому +12

    Thank you for your awesome videos and welcome back. I find the way you explain complex cyber security concepts easy to understand. If you have your own commercial CBTs or tutorial series I'd definitely buy

    • @TheCISOPerspective
      @TheCISOPerspective  2 роки тому +2

      Thank you for your support! I have contemplated doing a course focused on career growth and breaking into different fields within cybersecurity. Hoping to have some time to finish it in 2022

    • @dorahill
      @dorahill Рік тому

      Hello Looking for help to recover your 2FA, suspended hacked/disabled account back, PRESTINCODDING is the tech guy for the job. He helped me in retrieving both of my account back, after so many trials. I can now log into my account and save my middle school pictures.PRESTINCODDING
      Has 11k+ followers ok create a new account, and message him for help..

  • @punditgi
    @punditgi 2 роки тому +1

    Best security videos anywhere! 👍

    • @dorahill
      @dorahill Рік тому

      Hello Looking for help to recover your 2FA, suspended hacked/disabled account back, PRESTINCODDING is the tech guy for the job. He helped me in retrieving both of my account back, after so many trials. I can now log into my account and save my middle school pictures.PRESTINCODDING
      Has 11k+ followers ok create a new account, and message him for help..

  • @salmonela5278
    @salmonela5278 Рік тому

    great vid man. must step up my cibersecurity game.

  • @MsRope93
    @MsRope93 2 роки тому +3

    Very nice and useful. TNX

    • @dorahill
      @dorahill Рік тому

      Hello Looking for help to recover your 2FA, suspended hacked/disabled account back, PRESTINCODDING is the tech guy for the job. He helped me in retrieving both of my account back, after so many trials. I can now log into my account and save my middle school pictures.PRESTINCODDING
      Has 11k+ followers ok create a new account, and message him for help..

  • @Simonius95
    @Simonius95 2 роки тому +3

    Thank you so much for the great video!

  • @gauravtiwari2323
    @gauravtiwari2323 2 роки тому

    Very nice explanation.

    • @dorahill
      @dorahill Рік тому

      Hello Looking for help to recover your 2FA, suspended hacked/disabled account back, PRESTINCODDING is the tech guy for the job. He helped me in retrieving both of my account back, after so many trials. I can now log into my account and save my middle school pictures.PRESTINCODDING
      Has 11k+ followers ok create a new account, and message him for help..

  • @peterkim9696
    @peterkim9696 Рік тому

    Great explanation

    • @dorahill
      @dorahill Рік тому

      Hello Looking for help to recover your 2FA, suspended hacked/disabled account back, PRESTINCODDING is the tech guy for the job. He helped me in retrieving both of my account back, after so many trials. I can now log into my account and save my middle school pictures.PRESTINCODDING
      Has 11k+ followers ok create a new account, and message him for help..

  • @goodvibes4014
    @goodvibes4014 Рік тому

    What if we use the "Revoke All" option in gmail's security page, after changing the phone number?

  • @RobertinoMatausch
    @RobertinoMatausch Рік тому +1

    Great Video - I miss just one thing or maybe you will do it sooner or later .. a spotlight on the weakness of current biometrics...

    • @dorahill
      @dorahill Рік тому

      Hello Looking for help to recover your 2FA, suspended hacked/disabled account back, PRESTINCODDING is the tech guy for the job. He helped me in retrieving both of my account back, after so many trials. I can now log into my account and save my middle school pictures.PRESTINCODDING
      Has 11k+ followers ok create a new account, and message him for help..

    • @Freakinkat
      @Freakinkat Рік тому +1

      Biometrics can be exploited from things like well knowing that there are given numbers and spots that those things are stored on a specific givin place that can equally be tapped into and rewritten or erased entirely at the hardware level and that alone would not only get someone in the device or machine but essentially once that is gotten into or found out the where those things are stored, it's just getting to it, trial and error, and can they repeat the process. But if they do and can well once done the device is probably going to send information to the servers that there's been an update to the biometrics and that could be an even bigger problem if that happens. But then again what do I know

    • @VikashKumar-qk7bt
      @VikashKumar-qk7bt Рік тому

      Hello sir I want A help

    • @Freakinkat
      @Freakinkat Рік тому

      @@VikashKumar-qk7bt help what's the matter?

  • @HM-Shakil-Sarkar-53
    @HM-Shakil-Sarkar-53 Рік тому

    ❤❤❤❤

  • @nclsanluisrey4144
    @nclsanluisrey4144 2 місяці тому

    great video! Is there a video that shows exactly what every day people should be doing to best secure accounts? Like how to use the google authenticator? etc? recommendations would be awesome. Thanks!

  • @georgelefakis2305
    @georgelefakis2305 2 роки тому

    Okay so, I have a big problem i factory reset my phone and when i installed google authenticator and put the code it generates in my discord account it says that its invalid i dont know what to do and i need help and i wanna ask if im able to brute force it

    • @fizzaali2770
      @fizzaali2770 2 роки тому

      Same thing happened to me, were you able to find a solution?

    • @MoukhlesDerbal
      @MoukhlesDerbal 7 місяців тому

      Any solution?

  • @wicked5by5
    @wicked5by5 Рік тому

    Help my fb account was hacked I can't get in

  • @white2tamil823
    @white2tamil823 10 місяців тому

    Actually someone hacked my Gmail and they added 2FA ,anyone know how to recover it

    • @Johnnith
      @Johnnith 7 місяців тому

      I have been dealing with the same issue and I contacted support team with no response, causing frustration until I was referred to a professional named *havert_fixer* who helped me resolve the issue.

    • @Johnnith
      @Johnnith 7 місяців тому

      He has over 900 followers

    • @Johnnith
      @Johnnith 7 місяців тому

      He’s the best I can recommend for anyone that needs help

  • @sanukumar5763
    @sanukumar5763 Рік тому +1

    What is the Defense System of 4th MFA Attacks i.e Attack on Soft/Hard Tokens?

    • @dorahill
      @dorahill Рік тому

      Hello Looking for help to recover your 2FA, suspended hacked/disabled account back, PRESTINCODDING is the tech guy for the job. He helped me in retrieving both of my account back, after so many trials. I can now log into my account and save my middle school pictures.PRESTINCODDING
      Has 11k+ followers ok create a new account, and message him for help..

    • @glitchdigger
      @glitchdigger 8 місяців тому

      By keeping track of IP and client device fingerprinting & certificate and not allowing anomalous devices/IPs to perform logins.

  • @FayeDeeother99-fr2ye
    @FayeDeeother99-fr2ye 11 місяців тому

    Can you help me get back into my Google account....I tried but cannot...it's been 3 months and I'm afraid I will lose personal information. Two step isn't working...it's tied to that email....and an old phone number...

    • @Johnnith
      @Johnnith 7 місяців тому

      I have been dealing with the same issue and I contacted support team with no response, causing frustration until I was referred to a professional named *havert_fixer* who helped me resolve the issue.

    • @Johnnith
      @Johnnith 7 місяців тому

      He has over 900 followers

    • @Johnnith
      @Johnnith 7 місяців тому

      He’s the best I can recommend for anyone that needs helps

  • @user-23924
    @user-23924 Рік тому

    I got hacked and couldn't get into my account do to 2fa, need some help

    • @craigthompson3386
      @craigthompson3386 Рік тому +1

      Ivana has this solution you can reach her through her username on instagram below this comment

    • @craigthompson3386
      @craigthompson3386 Рік тому

      *Cyber.kor1*

    • @craigthompson3386
      @craigthompson3386 Рік тому

      shes got the right solution and she did mine perfectly

  • @jerrymathew2524
    @jerrymathew2524 2 роки тому

    Is there a good coder out here than can help me with evilginx setup? Lets deal. No ripper pls..

  • @OliveHay
    @OliveHay 2 роки тому +1

    My Facebook was hacked by someone who enabled 2-factor authentication. I was wondering if anybody could help me?
    Thanks

    • @lenitatomas7240
      @lenitatomas7240 Рік тому

      Have you had any luck ? Just happened to me too

    • @OliveHay
      @OliveHay Рік тому

      @@lenitatomas7240 Nope not yet! I'm trying again through Facebook Support where you send a picture of your passport / ID to be verified.
      In the last email, they said to reply with any further questions... I did just that, yet no reply! So I'm attempting again.
      FYI I've been locked out for about 1.5 years now! I'll be sure to let you know once I've had success.

    • @dorahill
      @dorahill Рік тому

      @@lenitatomas7240 Hello Looking for help to recover your 2FA, suspended hacked/disabled account back, PRESTINCODDING is the tech guy for the job. He helped me in retrieving both of my account back, after so many trials. I can now log into my account and save my middle school pictures.PRESTINCODDING
      Has 11k+ followers ok create a new account, and message him for help..

    • @OliveHay
      @OliveHay Рік тому

      @HarinHolaa Why are you spamming

    • @goat.8295
      @goat.8295 Рік тому

      Who is ZERRY CODINGS?? Cuz im having the same
      Provblem

  • @Freakinkat
    @Freakinkat Рік тому

    Waooowww well guess when I was using T-Mobile for my business and being janked outta 80k which I've no idea how my account even got to that level of stupid, it kinda was an ordeal.

  • @brianmoore3063
    @brianmoore3063 Рік тому

    "Via, some other method". 😅