BakkerJan / evilginx3

sturdy-chainsaw
49 stars 14 forks source link

M365 login - forwarded to device.login.domain.my #5

Closed maltic42 closed 5 months ago

maltic42 commented 5 months ago

Hi, after settings up Evilginx 3.2.0 with your M365 phishlet and configuring everything the following happens: after logging in to the URL (login.domain.my/randomtoken) I am prompted for a login, then a password. Both are logged. After that the browser is forwarded to device.login.domain.my and times out. I am not prompted for an MFA, I just get a browser message because of the timeout. I already created a DNS entry for device.login.domain.my, but this does not help. Any suggestions? Thanks!

Nemeziz50 commented 5 months ago

I’ll suggest reinstall it

Get Outlook for iOShttps://aka.ms/o0ukef


From: maltic42 @.> Sent: Tuesday, March 19, 2024 6:04:33 PM To: BakkerJan/evilginx3 @.> Cc: Subscribed @.***> Subject: [BakkerJan/evilginx3] M365 login - forwarded to device.login.domain.my (Issue #5)

Hi, after settings up Evilginx 3.2.0 with your M365 phishlet and configuring everything the following happens: after logging in to the URL (login.domain.my/randomtoken) I am prompted for a login, then a password. Both are logged. After that the browser is forwarded to device.login.domain.my and times out. I am not prompted for an MFA, I just get a browser message because of the timeout. I already created a DNS entry for device.login.domain.my, but this does not help. Any suggestions? Thanks!

— Reply to this email directly, view it on GitHubhttps://github.com/BakkerJan/evilginx3/issues/5, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AXQ277CY5TUWA3BKLYALERTYZB43DAVCNFSM6AAAAABE6CD6GGVHI2DSMVQWIX3LMV43ASLTON2WKOZSGE4TKNRTGY3TQNY. You are receiving this because you are subscribed to this thread.Message ID: @.***>

maltic42 commented 5 months ago

What do you recommend to reinstall? Evilginx?

Edit: Reinstalling Evilginx and deleting .evilginx does not work - same problem.

maltic42 commented 5 months ago

Nevermind, got it up and running, I had to make some changes to the phishlet. Thanks.