Skip to content

Comment on Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accountsparent

Comments

its a DNS hijack, redirecting connection to a registered domain, the page is a spoof of the workflow,with mitigation vs the MFA by abusing OAuth.

the page is HTTPS, an OAuth token is issued to the malignant client.

there is probably some WPAD malarchy in cases.

the entire workflow has minor variations but once an attacker has access to your M365 the chance of having everything you have done with M365 is very likely.

its not exactly MITM its more like Man Offside of the Middle

what happens next depends on the attackers objective.

But what about HSTS and HSTS preloading? This sounds more like a deauth/captive portal phish to me.

the hotspot was pwned and abused

this is a more detailed, and first order account of things from reliaquest itself.

https://reliaquest.com/blog/threat-spotlight-dns-poisoning-t...

apparently a full funnel VPN policy prevents the workflow.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.