I Stole a Microsoft 365 Account. Here's How.

I Stole a Microsoft 365 Account. Here's How.

Source: YouTube · John Hammond · published Nov 1, 2023 · 19:59

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates how to steal Microsoft 365 login credentials using Evil Jinx, a reverse proxy phishing framework that bypasses multi-factor authentication 0:00.

Key Takeaways:
• Evil Jinx acts as a man-in-the-middle reverse proxy, allowing attackers to intercept legitimate authentication sessions 0:38
• The setup process involves deploying Evil Jinx on a cloud server and configuring custom domains for the phishing attack 3:02
• Attackers create convincing phishing emails with malicious links to social engineering victims into entering credentials 12:31
• The tool captures username, password, and 2FA tokens while the victim unknowingly authenticates through the proxy 15:34
• Using stolen session cookies, attackers gain complete access to the victim's Microsoft 365 account without needing credentials 16:50

The demonstration highlights the effectiveness of social engineering attacks against cloud services and emphasizes that similar techniques can target any website, not just Microsoft 365 19:19.

Sources:

  • 0:00 Introduction to stealing Microsoft 365 credentials
  • 0:38 Explanation of Evil Jinx as reverse proxy framework
  • 3:02 Setting up Evil Jinx on cloud server
  • 12:31 Creating phishing email with malicious link
  • 15:34 Capturing credentials and 2FA tokens
  • 16:50 Using

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

I'm going to show you how to steal a Live Microsoft 365 login we'll get their username their password credentials bypass to factor authentication and have complete access to the account we are going to fool the user we're going to deceive them it's that trick known as social engineering with a little bit of fishing but we're going to take it one step further because we're going to use some cool techniques tools and tradecraft that make us be able to do this not just for Microsoft 365 but for any website across the internet because we are going to use a very special tool called evil Jinx now if you haven't heard of evil Jinx before it is a reverse proxy fishing framework that is able to bypass multiactor authentication but that reverse proxy tidbit is like the coolest thing in the world wha…