2 ms·
sounds like it's a simple software token. Hackers needed an account for this, which they got by paying 10$ for stolen cookies lol. So now they can log into so
by fierro 5y ago
sounds like it's a simple software token. Hackers needed an account for this, which they got by paying 10$ for stolen cookies lol. So now they can log into some random employees account, then get an admin issued 2FA code. Never seen these "bypass" codes before, but that's my best guess.
- bredren 5y agoThe stolen cookies imply full access to one of the employees machines. How is something like this advertised on forums? Valid auth token for employee at EA Games for sale? Does it list the expiration? Refunds if it isn’t valid at time of sale?
- fierro 5y agonah not to the full machine. This is just a Slack token. Someone basically had the employee click on something with XSS or some other way to steal cookies (idk there's a bunch of ways you can steal cookies out of someone's browser)