12.9K subscribers
550 photos
27 videos
24 files
890 links
This channel discusses:

— Offensive Security
— RedTeam
— Malware Research
— OSINT
— etc

Disclaimer:
t.me/APT_Notes/6

Chat Link:
t.me/APT_Notes_PublicChat
Download Telegram
Bypass 2FA Using noVNC

Steal credentials and bypass 2FA by giving users remote access to your server via an HTML5 VNC client that has a browser running in kiosk mode.

https://mrd0x.com/bypass-2fa-using-novnc/

#2fa #bypass #novnc
This media is not supported in your browser
VIEW IN TELEGRAM
🔑 YubiKeys Relaying Attack

That is, the APDU packets that the server application wants to get signed by a private key to verify the identity of the authentication. This attack works on all PIV Smart Cards.

Research:
Relaying YubiKeys Part 1
Relaying YubiKeys Part 2

Tools:
https://github.com/cube0x0/YubiKey-Relay

#ad #2fa #fido2 #ybikeys
👍5