WATCH: This hacker shows how to beat two-factor authentication

A security researcher, Chief Hacking Officer of company KnowBe4 Kevin Mitnick has developed a social engineering attack to breach two-factor authentication, TechCrunch reported.

In a public video, Mitnick produced a video on YouTube showing how the exploit works by sending victims to a fake login page.

The site requests your username, password, and authentication code, which it passes to the legitimate site to log you in, while capturing the session cookie in the process.

This is known as a phishing attack.

What is a phishing attack?

Phishing is the attempt of a hacker to obtain sensitive and personal information such as usernames, passwords, and credit card details, often for malicious reasons. 

Once this is done, the hacker can log in whenever they want, according to the report.

While the attack was demonstrated on LinkedIn, Mitnick’s company KnowBe4 warned that the attack could be weaponised for any site.

Additionally, Stu Sjouwerman, CEO of KnowBe4 told TechCrunch that anti-phishing education is deeply important and that a hack like this is impossible to complete if the victim is savvy about security and the dangers of clicking links that come into your email box.


In other hacker news, The Business Report team tested a tutorial earlier this year that was shown by a young female whose video received over 1,7 million views showing how she hacked her boyfriend's WhatsApp 

We tested the hacking process on both Android and Apple devices and the hack worked on both systems with relative ease.

It is worth noting that the video was first posted on Facebook 11 months ago, and yet there seem to be no security measures implemented by WhatsApp to prevent or notify this relatively easy hacking process.

For the original article and more fantastic tech news refer to the source.

Source: BusinessReport

Topics: session cookie capture, two factor authentication breach, Chief Hacking Officer, keynote speaker, KnowBe4, social engineering attack, Stu Sjuwerman, phishing attack, Kevin Mitnick

Latest Posts

Kevin offers three excellent presentations, two are based on his best-selling books. His presentations are akin to technology magic shows that educate and inform while keeping people on the edge of their seats. He offers expert commentary on issues related to information security and increases “security awareness.”

PCI Testing: Everything You Need To Know

Penetration testing is crucial for businesses to help ensure that their security posture will stand against threat actors. For businesses that handle ..

Read more ›

The 4 Phases of Penetration Testing

So, you’ve done your research on penetration testing and are ready for the pentest engagement. But before you choose just any pentesting vendor, it’s ..

Read more ›

What is Web Application Penetration Testing?

Is your company in the process of developing a new application? There are a lot of moving parts involved in developing and deploying cutting-edge appl..

Read more ›