logo

Purple Team Auth: Hacking & Bypassing MFA Systems, and How to Armor Up

Conference:  RSA Conference 2021

2021-05-17

Abstract

We will discuss failure modes of advanced authentication and show exploit bypasses of multifactor auth systems. From there, we will provide pragmatic means for defense of credential systems, including normalizing credential defense, baselines, credential reset engineering, and architecture of a "credential firewall" so that network firewalls aren't bypassed by unsafe credential practices.

Materials:

Tags:

Post a comment

Related work



Conference:  Defcon 31
Authors: Noam Moshe Vulnerability Researcher @ Claroty Team82, Sharon Brizinov Director of Security Research @ Claroty Team82
2023-08-01

Conference:  Black Hat Asia 2023
Authors: Gabriel Landau
2023-05-11