Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Phishing Windows Hello for Business - Exploiting Authentication Vulnerabilities

Black Hat via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Discover a critical security vulnerability in Windows Hello for Business (WHfB) through this Black Hat conference presentation that exposes how attackers can bypass its phishing-resistant authentication mechanism. Learn about the technical process of intercepting and modifying POST requests to Microsoft's authentication services, including the manipulation of parameters like User-Agent and isFidoSupported to force authentication downgrades. Explore the modified EvilGinx framework that automates and scales this attack vector, while understanding crucial mitigation strategies focused on conditional access policies and authentication strength enforcement. Gain valuable insights into WHfB's security architecture and the importance of implementing enhanced security measures to protect against such authentication downgrades.

Syllabus

Hook, Line and Sinker: Phishing Windows Hello for Business

Taught by

Black Hat

Reviews

Start your review of Phishing Windows Hello for Business - Exploiting Authentication Vulnerabilities

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.