DEF CON 33 - Turning Microsoft's Login Page into our Phishing Infrastructure - Keanu 'RedByte' Nys

DEF CON 33 - Turning Microsoft's Login Page into our Phishing Infrastructure - Keanu 'RedByte' Nys

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 43:00

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Summary: Abusing Microsoft's Login Infrastructure for Credential Theft

This presentation reveals multiple critical vulnerabilities in Microsoft's authentication infrastructure that allow attackers to steal user credentials while remaining entirely on Microsoft's trusted login domain (login.microsoftonline.com). The researcher declined Microsoft's repeated requests for preview slides, believing they would dismiss the vulnerabilities as not meeting servicing requirements.

Key Techniques Exploited:

1. Open Redirect Vulnerabilities

  • Federation-based redirects: Attackers configure a domain in their tenant with a sign-in URL pointing to a phishing page, crafting URLs that redirect users while appearing to use Microsoft's domain
  • App registration redirects: Creating app registrations with redirect URLs to phishing pages, bypassing consent prompts using parameters like "prompt=none"
  • Invalid scope redirects: Using invalid scope parameters that trigger errors after authentication, redirecting users to attacker-controlled sites even with restrictive consent settings

2. Self-Service Signup Exploitation

  • Attackers leverage self-service signup flows to collect custom attributes including "password" and "MFA code"
  • API connectors validate these credentials against Microsoft's infrastructure in real-time
  • Users remain on legitimate Microsoft domains while their credentials are captured and verified

3. Custom CSS Branding Manipulation

  • Despite Microsoft's filtering, researchers discovered ways to inject CSS that hide legitimate sign-in buttons
  • Attackers replace these with malicious buttons that redirect users to attacker-controlled sites
  • Using self-service password reset customization, attackers create convincing fake buttons positioned exactly where legitimate ones would appear

4. Advanced Domain Spoofing with Custom Fonts

  • Attackers register look-alike domains (e.g., micro-off.com) and create custom fonts where a hyphen character

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, welcome everyone to turning Microsoft login page into our fishing fishing infrastructure. And most importantly, welcome to our special guests from Microsoft, right? Welcome people from Microsoft because uh you guys really have to be my biggest fans. See, when my title and description got published by DevCon, I fairly quickly received an email from Microsoft's uh security response center asking me for a preview of my slides. However, the thing is before I um actually published this presentation to DevCon um I already made the decision that they would not be sharing anything with Microsoft and you'll be thinking okay but what about responsible disclosure then I agree actually but um the thing is if I would have reported this to Microsoft without this talk being a thing I know for …