RU version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
50% Positive
Analyzed from 153 words in the discussion.
Trending Topics
#page#mitm#dns#workflow#oauth#more#hsts#flow#urls#without

Discussion (4 Comments)Read Original on HackerNews
the page is HTTPS, an OAuth token is issued to the malignant client.
there is probably some WPAD malarchy in cases.
the entire workflow has minor variations but once an attacker has access to your M365 the chance of having everything you have done with M365 is very likely.
its not exactly MITM its more like Man Offside of the Middle
what happens next depends on the attackers objective.
Most people are so used to the login flow, they don't inspect the URLS if the page looks right. Some popups even obscure the URL (almost impossible to detect).