pushsecurity / saas-attacks

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
https://pushsecurity.com/blog/saas-attack-techniques/
Creative Commons Attribution 4.0 International
943 stars 61 forks source link

Potential new technique(s) - cell phone related compromise #29

Open jukelennings opened 11 months ago

jukelennings commented 11 months ago

1) SIM fraud for passwordless SMS logins or MFA bypassing 2) Persistence via similar methods by registered an adversary controlled phone number (as opposed to ghost logins)