How to Bypass Two-Factor Authentication – One Step at a Time
ID: d0cbb06d-10f4-534d-91ff-e15f74c0015c
STIX ID: report--d0cbb06d-10f4-534d-91ff-e15f74c0015c
Feed Name: Black Hills Infosec Blog
**Case study:** An attacker performed a password-spray to obtain credentials, used MailSniper via Exchange Web Services (EWS) to retrieve the victim's activation email (bypassing 2FA protections on OWA), then social-engineered the help desk to add a new 2FA device—allowing VPN authentication and internal access. Key failures were weak password policy, EWS accessible without 2FA, and inadequate help-desk authentication; recommended mitigations include strong passphrases, disabling or restricting EWS, and multi-factor provisioning controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
