Comment on Evilginx2: Standalone man-in-the-middle attack frameworkparentComments−dkuebric7yFrom a blog post by the tool's author:One of such defenses I uncovered during testing is using javascript to check if window.location contains the legitimate domain. These detections may be easy or hard to spot and much harder to remove, if additional code obfuscation is involved.
Comments
From a blog post by the tool's author: