kgretzky / evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
BSD 3-Clause "New" or "Revised" License
10.54k stars 1.91k forks source link

Phishlet for Bitwarden #804

Open thehackerish opened 2 years ago

thehackerish commented 2 years ago

Phishlet for Bitwarden web that supports 2FA. It captures the refresh_token which should be replayed manually to get the Bearer, then go to /api/sync to dump the database. Use only in Red Team or pentest engagements with your customers.