NEWS

Someone Has Figured Out How to Bypass Two-Factor Authentication

05/11/2018

5704

Security is not an easy thing at all, and while we may have thought that two-factor authentication was a protection against having our accounts hacked, a new exploit now allows hackers to spoof those authentication requests by sending users to fake login pages and subsequently stealing their username, password, and session cookie.


The exploit was shown by KNowBe4 Chief Hacking Officer Kevin Mitnick in a video that was made public today.


Someone Has Figured Out How to Bypass Two-Factor Authentication


The hack requires a user to visit a fake web site where their login, password, and authentication code could be stolen. At this point, the hacker can pass the correct credentials to a legitimate website before capturing the session cookie. This would allow a successful login, partly because the hack uses the same one-time two-factor authentication code as a way to spoof an authenticated login.


“A white hat hacker friend of Kevin’s developed a tool to bypass two-factor authentication using social engineering tactics – and it can be weaponized for any site,” said Stu Sjouwerman, CEO of KnowBe4 said. “Two-factor authentication is intended to be an extra layer of security, but in this instance, we clearly see that you can’t rely on it alone to protect your organization.”


That system was created by hacker Kuba Gretzky, who subsequently named it evilginx. Gretzky also detailed the whole thing in a post on his website, which makes for quite the read.


The only protection that would work against this method of attack would be to decrease the risk of phishing attacks on users, possibly via education. Technologically savvy users are unlikely to fall foul of such a hack, but with those who do not know better also being more likely to be fooled into visiting fake websites that look like the target site, the problem is most definitely a case of education.


“This highlights the need for new-school security awareness training and simulated phishing because people are truly your last line of defense,” according to Sjouwerman. We couldn’t agree more.


Source: redmond pie


Windows
Mac OS
iOS
Linux
3uTools
Win 64-bit For this device
V9.0 2025-11-11
Download
Win 32-bit For this device
V9.0 2025-11-11
Download
3uTools V3.18
2025-09-18
Please use the 3uTools PC client to install the iOS client:
1、 Install either the Windows or Mac version of 3uTools on your computer
2、 Open the PC client and connect your device to the computer via USB cable
3、 After the connection is successful, wait for the computer to automatically install the mobile app for the device, or locate “Install Mobile App” on the computer and manually click to install.
3uTools
deb file
v3.01 2025-11-20
Download
rpm file
v3.01 2025-11-20
Download
Windows
iOS
Android
3uAirPlayer
Win 64-bit For this device
V6.0.2 2025-11-19
Download
Win 32-bit For this device
V6.0.2 2025-11-19
Download
iOS Device Mirroring (No App Required)
1、 Install 3uAirplayer on the Windows PC
2、 Open Control Center and select Screen Mirroring
3、 From the list, choose your PC to start mirroring
4、 Or connect your iOS device to the PC via USB to begin mirroring
Scan to get "3uAirPlayer" App