12.9K subscribers
550 photos
27 videos
24 files
890 links
This channel discusses:

— Offensive Security
— RedTeam
— Malware Research
— OSINT
— etc

Disclaimer:
t.me/APT_Notes/6

Chat Link:
t.me/APT_Notes_PublicChat
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
🔑 YubiKeys Relaying Attack

That is, the APDU packets that the server application wants to get signed by a private key to verify the identity of the authentication. This attack works on all PIV Smart Cards.

Research:
Relaying YubiKeys Part 1
Relaying YubiKeys Part 2

Tools:
https://github.com/cube0x0/YubiKey-Relay

#ad #2fa #fido2 #ybikeys
👍5