I bought your tutorial guide so I followed it and made a cookies link, office cookies link but the issue in having is that when users are not inputting their credentials and I’m seeing cookies I tried importing the cookies but it’s not working I don’t know why it’s like that because I thought the cookies will work even if they login with fingerprint or something without inputting any credentials I don’t know if its possible or is there no way for them to login without putting credentials.
I’m kind of lost in-between somewhere here, I need your assistance.
1st u need to figure out what are main session cookes and on which other cookies it depends for example
usully session id is the main cookie but now website ombines that hash of the user if too so that if some one dose session hijack then it will not work .
—– this is just example ^—-
now u need to think same way and 1st identify cokkkies that u need to target and then use them also for injecting cookie make sure u are using correct plugin as most of the plugins dosent work properly
Okay thanks, also I have another question what can I do when Microsoft is redirecting users to the company/school sites to input their passwords after inputting the username in the landing page it is redirecting them to the school/company site and evilginx won’t intercept the password because it is not under the Microsoft domain I don’t know if you can assist me here on what to do in my Phishlets to intercept the password wherever the redirect goes to input password.