Search

Attacking Login Portals

Identify office usage by taking the CPOC email and seeing if it’s valid on the Microsoft email login

Password guessing strategies:

You can backdate the season+year like Winter2023 or Winter23. Or Summer2024

Location and teams. Example:

  • Pittsburgh could have passwords like: Steelers1!
  • Address
    • 578 Fake St
    • Password: Password578!
    • Local colleges

Generally start with:

  • MonthYear
  • SeasonYear
  • Company name
    • Tesla123!
    • T3sla, T3sl4, T35l4
Password Spraying O365 (Attacking O365)Password Spraying OWA (Outlook Web App)Attacking Other PortalsBypassing MFA/2FA