{"id":3006,"date":"2017-04-18T02:24:43","date_gmt":"2017-04-18T02:24:43","guid":{"rendered":"http:\/\/www.pir8geek.com\/?p=3006"},"modified":"2017-04-18T02:24:43","modified_gmt":"2017-04-18T02:24:43","slug":"evilginx-mitm-attack-framework-anadvanced-phishing-two-factor-authentication-bypass","status":"publish","type":"post","link":"https:\/\/www.jameseduard.com\/?p=3006","title":{"rendered":"Evilginx &#8211; MITM Attack Framework  anAdvanced Phishing with Two-factor Authentication Bypass"},"content":{"rendered":"<p><strong>Evilginx <\/strong>is a man-in-the-middle attack framework used for phishing credentials and session cookies of any web service. It&#8217;s core runs on Nginx HTTP server, which utilizes proxy_pass and sub_filter to proxy and modify HTTP content, while intercepting traffic between client and server.<br \/>\n<img decoding=\"async\" class=\"size-full wp-image-3007 aligncenter\" src=\"http:\/\/www.pir8geek.com\/wp-content\/uploads\/2017\/04\/evilginx-title.png\" alt=\"\" width=\"480\" height=\"82\" \/><\/p>\n<pre>Usage\nusage: evilginx_parser.py [-h] -i INPUT -o OUTDIR -c CREDS [-x]\noptional arguments:\n  -h, --help            show this help message and exit\n  -i INPUT, --input INPUT\n                        Input log file to parse.\n  -o OUTDIR, --outdir OUTDIR\n                        Directory where output files will be saved.\n  -c CREDS, --creds CREDS\n                        Credentials configuration file.\n  -x, --truncate        Truncate log file after parsing.\n<\/pre>\n<p>Example:<\/p>\n<pre>python evilginx_parser.py -i \/var\/log\/evilginx-google.log -o .\/logs -c google.creds\n<\/pre>\n<p>Video Demo:<br \/>\n<a href=\"https:\/\/vimeo.com\/212463675\">https:\/\/vimeo.com\/212463675<\/a><br \/>\n<strong>Note:<\/strong><br \/>\nEvilginx can be adapted to work with any website, not only with Google.<br \/>\n<strong>Disclaimer:<\/strong><br \/>\nThis project is released for educational purposes and should be used only in legitimate penetration testing assignments with written permission from to-be-phished parties.<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/github.com\/kgretzky\/evilginx\" target=\"_blank\" rel=\"noopener noreferrer\">Download Evilginx at GitHub<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Evilginx is a man-in-the-middle attack framework used for phishing credentials and session cookies of any web service. It&#8217;s core runs on Nginx HTTP server, which utilizes proxy_pass and sub_filter to proxy and modify HTTP content, while intercepting traffic between client and server. Usage usage: evilginx_parser.py [-h] -i INPUT -o OUTDIR -c CREDS [-x] optional arguments:<\/p>\n","protected":false},"author":1,"featured_media":3007,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[162,318],"tags":[461,544,671],"class_list":["post-3006","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-information-gathering","category-password-attacks","tag-mitm","tag-phishing","tag-phishing-attack"],"_links":{"self":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts\/3006","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3006"}],"version-history":[{"count":0,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts\/3006\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3006"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3006"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3006"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}