Skip to content

Comment on Evilginx2: Standalone man-in-the-middle attack frameworkparent

Comments

From a blog post by the tool's author:

One of such defenses I uncovered during testing is using javascript to check if window.location contains the legitimate domain. These detections may be easy or hard to spot and much harder to remove, if additional code obfuscation is involved.
AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.