• XSS.stack #1 – первый литературный журнал от юзеров форума

Icloud OTP code

You can try it through phishing, through a live panel.

Send an SMS to phone number with text where there is name of target, as much personal information as possible and a link to a live panel where the first page is personal information and button. Second page is a request OTP code

that is, target followed link to page with personal information. Operator receives notification in telegrams and enters the original by login and password. Target presses the "next" button and sees the code request form.

screen first page for example

1737205505122.png
 
you need to social engineer them, as an example you would say your james from apple support and theres been a recovery phone number request. and you basically explain that someone is impersonating them. then you would get them on panel by safeguarding there account or telling them we need to lock it then send the OTP code to there sms via apple website and phish them for it
 
you need to social engineer them, as an example you would say your james from apple support and theres been a recovery phone number request. and you basically explain that someone is impersonating them. then you would get them on panel by safeguarding there account or telling them we need to lock it then send the OTP code to there sms via apple website and phish them for it
that works, but somehow on the SE, would be good have the Apple ID or some to be more legit on the screen
 
I have icloud live telegram panel. message me for further details
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх