MAIF / otoroshi

Lightweight api management on top of a modern http reverse proxy
https://www.otoroshi.io
Apache License 2.0
236 stars 37 forks source link

Support bypass 2fa? #1934

Closed Dazmed707 closed 2 weeks ago

Dazmed707 commented 4 weeks ago

This tool capture cookies in google for bypass 2fa¡

mathieuancelin commented 3 weeks ago

Hey @Dazmed707 can you elaborate a bit more on what you want to achieve ?

Dazmed707 commented 3 weeks ago

I want it to capture session cookies from a specific page, like evilginx does but without phishlets

mathieuancelin commented 3 weeks ago

As otoroshi stands between the client and the backend, you can virtually do whatever you want with the http traffic even with TLS enabled as otoroshi do the TLS termination