kgretzky / evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
BSD 3-Clause "New" or "Revised" License
10.62k stars 1.92k forks source link

Does evilginx have an endpoint to send custom data/tokens? #752

Closed UndergroundLabs closed 1 year ago

UndergroundLabs commented 2 years ago

I am using Javascript inject to get some values from the page. I need these values stored, does Evilginx have an endpoint where I can send these tokens so they appear in the session list?

For example, if the page has some tokens in the HTML that I want to grab with Javascript, can I make an ajax request to evilginx to store this data with the session?

JM-Lemmi commented 2 years ago

No, Evilginx currently does not have this functionality.

ghost commented 2 years ago

you can create a custom credential capture regex. get the tokens via javascript then post them against evilginx2 so they are picked up as credentials.

Support-1535 commented 1 year ago

Hello! If you were already able to resolve your doubts and achieve your goals, close the issue so that we know which ones are pending.

Thank you!

If you want expedited help and have the assistance of many professional people, join our private group. Contact us support@evilginx2.com to give you access to the group.