Light

Episode #888 Quiz

The EvilProxy Service
Date: 2022-09-13 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

EvilProxy is a turnkey Phishing-as-a-Service platform that uses transparent reverse proxies and cookie injection to steal usernames, passwords, session cookies, and one-time MFA tokens from targets visiting spoofed login pages. Hosted via Tor, it offers point-and-click campaigns, customer vetting, and per-period subscriptions, enabling account takeover and supply-chain compromise.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What was the key operational reason EvilProxy was so dangerous compared with earlier, harder-to-use attack tooling, according to the episode?
Question 2: Which authentication elements did EvilProxy claim to bypass by proxying the victim's login session?
Question 3: How did EvilProxy obtain the victim's credentials and session material during a phishing attack?
Question 4: What pricing model did the EvilProxy control panel show for access to the service?
Question 5: Which combination of platforms was explicitly called out as supported by EvilProxy for phishing targets?
Cancel