Wolfgang Goerlich's Stuck In Traffic

Bypassing Outlook's Two-Factor Authentication

Informações:

Sinopse

Microsoft Exchange and Outlook Web Access feature two-factor authentication. A password. A token. But turns out, the Web Services doesn't. And this means we can bypass 2FA. Here's the attack and defense.