Researcher can bypass 2-step verification via WebView2 to steal cookies – Computer – News

A security researcher has developed a phishing technology that uses Microsoft WebView2 features to steal victim login credentials and cookies. This can bypass two-step verification.

Phishing attack detected by researcher WebView2-Cookie-Stealer It uses the standard features of the WebView2 website embedding tool and a deceptive program to steal user browser cookies. Entering specific JavaScript code on the login page for legitimate websites makes it appear as if it were a normal login process. In principle, the victim logs in as usual, but then via the attacker’s malware. This makes it possible, for example, to record user key entries using a keylogger program.

Once the victim logs in, with or without the two-step verification application, the attacker can copy the cookies stored by the browser. The malicious hacker can then use these authentication cookies for their own session, so that the website believes they are identifying the attacker as a legitimate user. Stolen cookies including login details can be imported into a new session via the Chrome extension EditThisCookie, for example.

According to the security researcher, the vulnerability is based on social engineering† The victim must initially run the WebView2 executable before monitoring an attempt to log in to a legitimate website. Microsoft confirms in response to the computer asleep Therefore, users should never run or install applications if they come from an untrustworthy source.

The software giant also states that users should always run an antivirus like Microsoft Defender to prevent rogue applications from being installed. jax finished By the way, Defender did not stop the installation of the beta application for the security researcher, but only issued a warning.

The security researcher disguises his spoofed application as an Office application, after which users formally sign in to Microsoft via WebView2 embed
Derek Atkinson

Derek Atkinson

"Web maven. Infuriatingly humble beer geek. Bacon fanatic. Typical creator. Music expert."

Leave a Reply

Your email address will not be published. Required fields are marked *

bunny girls hentai hentaitgp.com hutoshi miyako tomcat
pakistansex vegasmpegs.info pokemon in hindi
النائمة سكس pornhauz.com اللعب فى الكس
regine ogie duet philteleserye.com darren espanto
morganaramirez freesexcams.pro royalgirls_x stripchat
www sexi video hd com chupatube.info femout
gmanetwork com maria clara watchteleserye.com mga kasalanan
punjabi sexi kand japaneseporntrends.com pic pussy
宮野瞳 sakurajav.mobi 深田えいみ 無修正
animal fuck tubenza.mobi sada hot kiss
japanese mom and son xnxx pakistanipornx.net college xnxx
www xxxindan sexkrug.com tamil pengal sex
hindi xxx.com dungtube.info tubexclip
مواقعسكس slutswile.net سكس روسي مترجم
video blue originalhindiporn.mobi indian sex kannada