kgretzky / evilginx

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2
MIT License
1.06k stars 260 forks source link

Ho can I protect my websites from this? #60

Open ghost opened 6 years ago

ghost commented 6 years ago

@kgretzky thanks for your amazing works!

I have many websites, in many technologies... I need a way to protect them.

I'm wondering if there is just something like a check of suspicious IP activities in the aftermath?

Just this? Really?

Can I check my SSL certificate? HSTS? Avoid serving my site if called from evilnginx?

CSRF protection helps in any way?

moloch-- commented 2 years ago

U2F