Generated by All in One SEO v4.9.2, this is an llms.txt file, used by LLMs to index the site. # TzuSec.com Cybersecurity Demystified ## Sitemaps - [XML Sitemap](https://tzusec.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [How to run Gophish as a systemd service](https://tzusec.com/how-to-run-gophish-as-a-systemd-service/) - Learn how to run Gophish as a systemd service on your Linux server. Follow these step-by-step instructions to improve your phishing campaign management. - [Find all non-default services on you Windows machine with Powershell](https://tzusec.com/find-all-non-default-services-on-you-windows-machine-with-powershell/) - I just released a new video on Youtube where I show you how to use my new Powershell script for getting a list of all services that run on your windows machine that are not default services. You probably won't need a video instruction on how to run a simple Powershell script but I'm sure - [how to use Evilginx2 to grab session tokens and bypass Multi-factor authentication](https://tzusec.com/how-to-use-evilginx2-to-grab-session-tokens-and-bypass-multi-factor-authentication/) - Today I want to show you a demo that I recorded on how you can use the amazing tool Evilginx2 (by Kuba Gretzky) to bypass Multi-Factor Authentication (MFA). In the demo I used Evilginx on a live Microsoft 365/Office 365 environment but It can be used on almost any site that doesn't use a more - [How to launch Command Prompt and powershell from MS Paint](https://tzusec.com/how-to-launch-command-prompt-and-powershell-from-ms-paint/) - This guide will show you how you can launch cmd and Powershell with help from Microsoft Paint. Sometimes organisations environments are being locked down and are preventing users from right clicking and opening tools such as cmd.exe or powershell.exe. When I face that during a penetration test I usually try this simple mspaint hack to - [How to download files with Certutil.exe](https://tzusec.com/how-to-download-files-with-certutil-exe/) - This quick guide will show you a simple way of downloading files with certutil.exe. It's pretty handy to use when other tools for downloading files (for example powershell) are disabled. Since certutil.exe is a built-in windows tool it normally isn't blocked. The command you want to run to download a file: certutil.exe -urlcache -f http:///file.exe - [What is DKIM and how do you enable IT in Microsoft 365?](https://tzusec.com/what-is-dkim-and-how-do-you-enable-it-in-microsoft-365/) - What is DKIM? DKIM stands for DomainKeys Identified Mail and is an email autentication method. It helps the receiving mail server to verify whether an email have been sent from an allowed email server or not. The idea of DKIM is that the senders email servers are signing all outgoing messages with asymmetric encryption. The - [What is SPF and how do you configure it?](https://tzusec.com/what-is-spf-and-how-do-you-configure-it/) - What is SPF? SPF stands for Sender Policy Framework and is an email autentication method. It helps the receiving mail server to verify whether an email have been sent from an allowed email server or not. Your SPF policy is set up by publishing it in the form of a TXT record in your DNS. - [How to prepare your CentOS 6 machine to Microsoft Azure](https://tzusec.com/how-to-prepare-your-centos-6-machine-to-microsoft-azure/) - This guide will help you prepare your CentOS 6 server for a migration from on-premise to Microsoft Azure cloud. It can be a bit tricky to get everything to work correctly and personally I didn't find Microsofts guides to be great so I write this post to help you with the steps that is needed - [How to prepare your CentOS 7 machine to Microsoft Azure](https://tzusec.com/how-to-prepare-your-centos-7-machine-to-microsoft-azure/) - This guide will help you prepare your CentOS 7 server for a migration from on-premise to Microsoft Azure cloud. It can be a bit tricky to get everything to work correctly and personally I didn't find Microsofts guides to be great so I write this post to help you with the steps that is needed - [Brute Forcing With Hydra](https://tzusec.com/brute-forcing-with-hydra/) - What is Hydra: Hydra is a classic, fast network logon cracker that was created by Van Hauser. It is commonly used as a network logon cracker. The tool is great since it's both fast and have built-in support for many different protocols. You can find the code at: https://github.com/vanhauser-thc/thc-hydra How to install Hydra: Hydra comes - [How to Install Terraform in Linux](https://tzusec.com/how-to-install-terraform-in-linux/) - Terraform is an open-source software tool for Infrastructure as Code (IaC). The tool helps users to define and provision a cloud infrastructure with code. This guide will guide you on how to install Terraform on Linux. You can either install Terraform from pre-compiled binary or you can also compile it from source and that this - [ZeroLogon - How to Exploit and Mitigate](https://tzusec.com/zerologon-how-to-exploit-and-fix/) - Information about vulnerability The vulnerability I will discuss in this post it the famous ZeroLogon vulnerability(CVE-2020-1472). By exploiting the vulnerability any attacker with network access to domain controller can take complete control of a windows domain very quick and easy. I will start off by showing you how easy you can exploit the vulnerability. Then - [How to Backup and Restore phpIPAM](https://tzusec.com/backup-and-restore-phpipam/) - phpIPAM is an awesome IP address management application. I have used it for many years and really like it. In this guide I will show you how you can schedule automatic backups of your IPAM and how you easily can restore the database if something goes wrong. Schedule automatic backups Create backup foldermkdir /mnt/backups/phpipam/db/Create a - [Review - Terraform Associate Certification](https://tzusec.com/review-terraform-associate-certification/) - What is Terraform Terraform is an open-source software tool for IaC created by HashiCorp. The tool helps users to define and provision a cloud infra the Hashicorp Configuration Language (HCL), or optionally JSON. Three days ago they also released a CDK with Python and Typescript support. Terraform supports most of the big of cloud infrastructure - [Cracking KeePass Database](https://tzusec.com/cracking-keepass-database/) - In this post I will describe how you can crack a KeePass Database file (.kdbx) in an easy way. Or to be correct we are not cracking the DB, we are cracking the password hash. To demonstrate this I created a new database that I called "SecretDB.kdbx" and our mission will be to find out - [How to crack hashes with John the Ripper - Linux](https://tzusec.com/crack-password-hashes-from-linux-with-john-the-ripper/) - In this post I will show you how you can crack passwords with John the Ripper. We will start off by collecting the hashes from a linux machine, then use the tool unshadow and at last crack the hashes with John the Ripper. 1 - Collect hashes from a Linux machineWe will start with collecting - [Grab All WiFi Passwords with just One Line of Code](https://tzusec.com/grab-all-wifi-passwords-with-just-one-line-of-code/) - I just released a new video on my Youtube channel. The video will show you how you easily can grab SSID and password to all wireless that your Windows computer remember with a oneliner. The command first lists all wlan profiles and then saves the SSID to a variable ($name). After that the password is - [How to Install Golang in Kali Linux](https://tzusec.com/how-to-install-golang-in-kali-linux/) - Golang (Go) is a programming language that are becoming more and more popular and I have seen many interesting tools that are written in Go. Since Go are not being installed by default in Kali Linux I thought that publishing a quick-start guide could be a good idea. Start by open your web browser and - [Grab login credentials with a BadUSB](https://tzusec.com/grab-login-credentials-with-a-badusb/) - I just released a new video on my Youtube channel. The video will show you some things that can be done with a BadUSB. A BadUSB is a device that simulates a HID in form of a keyboard and takes advantage of that the majority of today's computers blindly trusts all USB-devices. The computer thinks - [O.MG-CABLE - How To Get Started](https://tzusec.com/o-mg-cable-how-to-get-started/) - This guide will help you get started with the O.MG-cable. When you open your package it should include three things: A card with instructions The programmerThe OMG-cable If you read the instruction card you will see that you can find instructions on how to get started at https://o.mg.lol/setup. You will there find a link to - [How to use Undercover-mode in Kali Linux](https://tzusec.com/how-to-use-undercover-mode-in-kali-linux/) - Yesterday a new version of Kali Linux were released, Kali 2020.1. You can download it here. Make sure that you have read the release notes to make sure that you don't break anything you don't want. Upgrade your existing machine: Run sudo apt full-upgrade -y Wait for the job to finish.Verify that you got the - [omg-cable finally arrived](https://tzusec.com/omg-cable-finally-arrived/) - Since @_MG_ posted the first video of his O.MG-cable about a year ago I have been so excited and followed his work closely from twitter and on his blog . Now the cable can be bought in hak5s shop and as soon as it was available in the shop I placed an order. I really - [Cewl](https://tzusec.com/cewl/) - This is the first blog post in my series where I will go through all built-in Kali Linux tools. I will write information about how the tools work and give you examples on when to use them. This will be an excellent way for me to learn the tools in depth and hopefully it can - [Crunch](https://tzusec.com/crunch/) - Today I will continue to write about tools that you can use to generate wordlists. Today we will take a look at crunch. Background and the functionality:Crunch is another great tool that can be used to create wordlists. The tool was initially released in 2004 and the author is bofh28 according to tools.kali.org.You use the - [Security Fest 2019](https://tzusec.com/security-fest-2019/) - This year’s amazing Security Fest has now come to an end. I've had two really great days where I learned a lot and got new inspiration and ideas to work with. Christoffer Jerkeby – Load Balancer with RCE, Hacking F5 My favorite talk from this conference that I want to write a bit about was - [How to connect to Azure with SSH Tunneling](https://tzusec.com/how-to-connect-to-azure-with-ssh-tunneling/) - Have you just created your first Azure VM and are looking for a good, secure way to connect to you new machine without exposing more than necessary to the internet? Maybe you just want to run a few machines and don't want to spend money on firewalls to configure VPN to your Azure Virtual Network - [Httprobe](https://tzusec.com/httprobe/) - This post is about httprobe which is a tool for quickly probing for active http and https servers. If you have a list with subdomains you can quickly check which are active by using this tool. Httprobe is available on Github and the tool was created by Tom Hudson (@tomnomnom on Twitter). Pre requisites: 1. - [Assetfinder](https://tzusec.com/assetfinder/) - In this post I will write a bit about Assetfinder which is an quick and awesome tool for finding subdomains. The tool is available in Github and was created by Tom Hudson (@tomnomnom on Twitter). According to the information on Github, Assetfinder uses the following resources to find subdomains crt.sh certspotter hackertarget threatcrowd wayback machine - [Don’t get phished this holiday season](https://tzusec.com/dont-get-phished-this-holiday-season/) - Holiday season is coming closer and I would like to take this opportunity to discuss phishing since the amount of phishing attacks increases a lot during holiday season. According to Zscaler the amount of phishing attacks increased with 400% from October to November this year as Black Friday and Cyber Monday came closer. Phishing, which - [sqrl - steve gibson @owasp gbg](https://tzusec.com/sqrl-steve-gibson-owasp-gbg/) - Last week I attended my first OWASP-event and the event was hold i Gothenburg, Sweden. Before I read about this event I hadnt heard about SQRL (Secure Quick Reliable Login) but the enthusiastic presentation by the author himself, Steve Gibson got me hooked. I really like the idea of SQRL as a replacement for username ## Pages - [About](https://tzusec.com/about/) - My name is Rickard Carlsson and I use this website to share my thoughts, ideas and tools. It will probably be most security related stuff since that is my number one passion. If you have questions feel free to contact me on Twitter - @tzusec Disclaimer:All content on this site is for educational purposes only. ## Categories - [Tools](https://tzusec.com/category/tools/) - [Guides](https://tzusec.com/category/guides/) - [Thoughts](https://tzusec.com/category/thoughts/) - [Events](https://tzusec.com/category/events/) - [Password attacks](https://tzusec.com/category/guides/kali-linux/password-attacks/) - [Kali Linux](https://tzusec.com/category/guides/kali-linux/) - [How to](https://tzusec.com/category/guides/how-to/) - [Reconnaissance](https://tzusec.com/category/guides/kali-linux/recon/) - [Videos](https://tzusec.com/category/videos/) ## Tags - [#securityfest](https://tzusec.com/tag/securityfest/) - [#2019](https://tzusec.com/tag/2019/) - [F5](https://tzusec.com/tag/f5/) - [RCE](https://tzusec.com/tag/rce/) - [BIG-IP](https://tzusec.com/tag/big-ip/) - [IoT](https://tzusec.com/tag/iot/) - [owasp](https://tzusec.com/tag/owasp/) - [gbg](https://tzusec.com/tag/gbg/) - [SQRL](https://tzusec.com/tag/sqrl/) - [Steve](https://tzusec.com/tag/steve/) - [Gibson](https://tzusec.com/tag/gibson/) - [authentication](https://tzusec.com/tag/authentication/) - [kali](https://tzusec.com/tag/kali/) - [linux](https://tzusec.com/tag/linux/) - [cewl](https://tzusec.com/tag/cewl/) - [password](https://tzusec.com/tag/password/) - [attack](https://tzusec.com/tag/attack/) - [crack](https://tzusec.com/tag/crack/) - [custom](https://tzusec.com/tag/custom/) - [wordlist](https://tzusec.com/tag/wordlist/) - [secvibe](https://tzusec.com/tag/secvibe/) - [crunch](https://tzusec.com/tag/crunch/) - [list](https://tzusec.com/tag/list/) - [word](https://tzusec.com/tag/word/) - [Azure](https://tzusec.com/tag/azure/) - [Putty](https://tzusec.com/tag/putty/) - [Firefox](https://tzusec.com/tag/firefox/) - [Chrome](https://tzusec.com/tag/chrome/) - [Google](https://tzusec.com/tag/google/) - [Mozilla](https://tzusec.com/tag/mozilla/) - [SSH](https://tzusec.com/tag/ssh/) - [VM](https://tzusec.com/tag/vm/) - [NSG](https://tzusec.com/tag/nsg/) - [IP](https://tzusec.com/tag/ip/) - [SimpleHTTPServer](https://tzusec.com/tag/simplehttpserver/) - [Simple](https://tzusec.com/tag/simple/) - [Guide](https://tzusec.com/tag/guide/) - [python](https://tzusec.com/tag/python/) - [Windows 10](https://tzusec.com/tag/windows-10/) - [connect](https://tzusec.com/tag/connect/) - [HowTo](https://tzusec.com/tag/howto/) - [phishing](https://tzusec.com/tag/phishing/) - [scam](https://tzusec.com/tag/scam/) - [holiday](https://tzusec.com/tag/holiday/) - [malware](https://tzusec.com/tag/malware/) - [94%](https://tzusec.com/tag/94/) - [email](https://tzusec.com/tag/email/) - [golang](https://tzusec.com/tag/golang/) - [go](https://tzusec.com/tag/go/) - [programming](https://tzusec.com/tag/programming/) - [how](https://tzusec.com/tag/how/) - [to](https://tzusec.com/tag/to/) - [install](https://tzusec.com/tag/install/) - [helloworld](https://tzusec.com/tag/helloworld/) - [reconnaissance](https://tzusec.com/tag/reconnaissance/) - [recon](https://tzusec.com/tag/recon/) - [tool](https://tzusec.com/tag/tool/) - [assetfinder](https://tzusec.com/tag/assetfinder/) - [github](https://tzusec.com/tag/github/) - [subdomains](https://tzusec.com/tag/subdomains/) - [domains](https://tzusec.com/tag/domains/) - [domain](https://tzusec.com/tag/domain/) - [finder](https://tzusec.com/tag/finder/) - [httprobe](https://tzusec.com/tag/httprobe/) - [http](https://tzusec.com/tag/http/) - [https](https://tzusec.com/tag/https/) - [probe](https://tzusec.com/tag/probe/) - [active](https://tzusec.com/tag/active/) - [tomnomnom](https://tzusec.com/tag/tomnomnom/) - [OMG-cable](https://tzusec.com/tag/omg-cable/) - [OMG](https://tzusec.com/tag/omg/) - [CABLE](https://tzusec.com/tag/cable/) - [O.MG-cable](https://tzusec.com/tag/o-mg-cable/) - [Hak5](https://tzusec.com/tag/hak5/) - [BadUSB](https://tzusec.com/tag/badusb/) - [lightning](https://tzusec.com/tag/lightning/) - [kalilinux](https://tzusec.com/tag/kalilinux/) - [undercover](https://tzusec.com/tag/undercover/) - [2020.1](https://tzusec.com/tag/2020-1/) - [upgrade](https://tzusec.com/tag/upgrade/) - [Windows](https://tzusec.com/tag/windows/) - [Windows10](https://tzusec.com/tag/windows10/) - [O.MG](https://tzusec.com/tag/o-mg/) - [MG](https://tzusec.com/tag/mg/) - [hack](https://tzusec.com/tag/hack/) - [flashing](https://tzusec.com/tag/flashing/) - [firmware](https://tzusec.com/tag/firmware/) - [get](https://tzusec.com/tag/get/) - [started](https://tzusec.com/tag/started/) - [login](https://tzusec.com/tag/login/) - [wifi](https://tzusec.com/tag/wifi/) - [malduino](https://tzusec.com/tag/malduino/) - [maltronics](https://tzusec.com/tag/maltronics/) - [poc](https://tzusec.com/tag/poc/) - [rubberducky](https://tzusec.com/tag/rubberducky/) - [powershell](https://tzusec.com/tag/powershell/) - [uac](https://tzusec.com/tag/uac/) - [bypass uac](https://tzusec.com/tag/bypass-uac/) - [bypass](https://tzusec.com/tag/bypass/) - [payload](https://tzusec.com/tag/payload/) - [oneliner](https://tzusec.com/tag/oneliner/) - [grab](https://tzusec.com/tag/grab/) - [wireless](https://tzusec.com/tag/wireless/) - [profile](https://tzusec.com/tag/profile/) - [unshadow](https://tzusec.com/tag/unshadow/) - [john the ripper](https://tzusec.com/tag/john-the-ripper/) - [john](https://tzusec.com/tag/john/) - [shadow](https://tzusec.com/tag/shadow/) - [hash](https://tzusec.com/tag/hash/) - [/etc/passwd](https://tzusec.com/tag/etc-passwd/) - [/etc/shadow](https://tzusec.com/tag/etc-shadow/) - [rockyou](https://tzusec.com/tag/rockyou/) - [keepass](https://tzusec.com/tag/keepass/) - [database](https://tzusec.com/tag/database/) - [db](https://tzusec.com/tag/db/) - [keepass2john](https://tzusec.com/tag/keepass2john/) - [hashcat](https://tzusec.com/tag/hashcat/) - [dictionary](https://tzusec.com/tag/dictionary/) - [terraform](https://tzusec.com/tag/terraform/) - [certification](https://tzusec.com/tag/certification/) - [associate](https://tzusec.com/tag/associate/) - [hashicorp](https://tzusec.com/tag/hashicorp/) - [study](https://tzusec.com/tag/study/) - [review](https://tzusec.com/tag/review/) - [cloud](https://tzusec.com/tag/cloud/) - [studyplan](https://tzusec.com/tag/studyplan/) - [Windows Server 2019](https://tzusec.com/tag/windows-server-2019/) - [non-default](https://tzusec.com/tag/non-default/) - [malicious](https://tzusec.com/tag/malicious/) - [services](https://tzusec.com/tag/services/) - [tzusec](https://tzusec.com/tag/tzusec/) - [phpipam](https://tzusec.com/tag/phpipam/) - [ipam](https://tzusec.com/tag/ipam/) - [backup](https://tzusec.com/tag/backup/) - [restore](https://tzusec.com/tag/restore/) - [automate](https://tzusec.com/tag/automate/) - [automatic](https://tzusec.com/tag/automatic/) - [backups](https://tzusec.com/tag/backups/) - [mariadb](https://tzusec.com/tag/mariadb/) - [crontab](https://tzusec.com/tag/crontab/) - [cron](https://tzusec.com/tag/cron/) - [bash](https://tzusec.com/tag/bash/) - [script](https://tzusec.com/tag/script/) - [zerologon](https://tzusec.com/tag/zerologon/) - [vulnerability](https://tzusec.com/tag/vulnerability/) - [cve-2020-1472](https://tzusec.com/tag/cve-2020-1472/) - [CVSS](https://tzusec.com/tag/cvss/) - [admin](https://tzusec.com/tag/admin/) - [netlogon](https://tzusec.com/tag/netlogon/) - [impacket](https://tzusec.com/tag/impacket/) - [set_empty_pw](https://tzusec.com/tag/set_empty_pw/) - [secretdump](https://tzusec.com/tag/secretdump/) - [wmiexec](https://tzusec.com/tag/wmiexec/) - [microsoft](https://tzusec.com/tag/microsoft/) - [mitigation](https://tzusec.com/tag/mitigation/) - [iac](https://tzusec.com/tag/iac/) - [infrastructure](https://tzusec.com/tag/infrastructure/) - [as](https://tzusec.com/tag/as/) - [code](https://tzusec.com/tag/code/) - [source](https://tzusec.com/tag/source/) - [open-source](https://tzusec.com/tag/open-source/) - [hydra](https://tzusec.com/tag/hydra/) - [cracking](https://tzusec.com/tag/cracking/) - [brute-force](https://tzusec.com/tag/brute-force/) - [brute](https://tzusec.com/tag/brute/) - [force](https://tzusec.com/tag/force/) - [ftp](https://tzusec.com/tag/ftp/) - [http-post](https://tzusec.com/tag/http-post/) - [telnet](https://tzusec.com/tag/telnet/) - [example](https://tzusec.com/tag/example/) - [CentOS6](https://tzusec.com/tag/centos6/) - [CentOS](https://tzusec.com/tag/centos/) - [transformation](https://tzusec.com/tag/transformation/) - [lift](https://tzusec.com/tag/lift/) - [and](https://tzusec.com/tag/and/) - [shift](https://tzusec.com/tag/shift/) - [console](https://tzusec.com/tag/console/) - [secureetty](https://tzusec.com/tag/secureetty/) - [grub](https://tzusec.com/tag/grub/) - [initramfs](https://tzusec.com/tag/initramfs/) - [dracut](https://tzusec.com/tag/dracut/) - [ifcfg](https://tzusec.com/tag/ifcfg/) - [waagent](https://tzusec.com/tag/waagent/) - [walinuxagent](https://tzusec.com/tag/walinuxagent/) - [ttys0](https://tzusec.com/tag/ttys0/) - [CentOS7](https://tzusec.com/tag/centos7/) - [serial-getty](https://tzusec.com/tag/serial-getty/) - [spf](https://tzusec.com/tag/spf/) - [txt](https://tzusec.com/tag/txt/) - [dns](https://tzusec.com/tag/dns/) - [eli5](https://tzusec.com/tag/eli5/) - [configure](https://tzusec.com/tag/configure/) - [sender](https://tzusec.com/tag/sender/) - [policy](https://tzusec.com/tag/policy/) - [framework](https://tzusec.com/tag/framework/) - [dmarc](https://tzusec.com/tag/dmarc/) - [mxtoolbox](https://tzusec.com/tag/mxtoolbox/) - [dmarcadvisor](https://tzusec.com/tag/dmarcadvisor/) - [dig](https://tzusec.com/tag/dig/) - [Microsoft365](https://tzusec.com/tag/microsoft365/) - [DKIM](https://tzusec.com/tag/dkim/) - [enable](https://tzusec.com/tag/enable/) - [CNAME](https://tzusec.com/tag/cname/) - [selector](https://tzusec.com/tag/selector/) - [selector1](https://tzusec.com/tag/selector1/) - [selector2](https://tzusec.com/tag/selector2/) - [domainkey](https://tzusec.com/tag/domainkey/) - [onmicrosoft.com](https://tzusec.com/tag/onmicrosoft-com/) - [asymmetric](https://tzusec.com/tag/asymmetric/) - [encryption](https://tzusec.com/tag/encryption/) - [autentication](https://tzusec.com/tag/autentication/) - [exhange](https://tzusec.com/tag/exhange/) - [online](https://tzusec.com/tag/online/) - [EXO](https://tzusec.com/tag/exo/) - [certutil.exe](https://tzusec.com/tag/certutil-exe/) - [certutil](https://tzusec.com/tag/certutil/) - [download](https://tzusec.com/tag/download/) - [files](https://tzusec.com/tag/files/) - [urlcache](https://tzusec.com/tag/urlcache/) - [blocked](https://tzusec.com/tag/blocked/) - [launch](https://tzusec.com/tag/launch/) - [cmd.exe](https://tzusec.com/tag/cmd-exe/) - [powershell.exe](https://tzusec.com/tag/powershell-exe/) - [command prompt](https://tzusec.com/tag/command-prompt/) - [paint](https://tzusec.com/tag/paint/) - [mspaint](https://tzusec.com/tag/mspaint/) - [pentest](https://tzusec.com/tag/pentest/) - [.bmp](https://tzusec.com/tag/bmp/) - [.bat](https://tzusec.com/tag/bat/) - [24-bit](https://tzusec.com/tag/24-bit/) - [bitmap](https://tzusec.com/tag/bitmap/) - [RGB](https://tzusec.com/tag/rgb/) - [pixel](https://tzusec.com/tag/pixel/) - [office365](https://tzusec.com/tag/office365/) - [evilginx](https://tzusec.com/tag/evilginx/) - [evilginx2](https://tzusec.com/tag/evilginx2/) - [phishlets](https://tzusec.com/tag/phishlets/) - [yaml](https://tzusec.com/tag/yaml/) - [o365](https://tzusec.com/tag/o365/) - [burp](https://tzusec.com/tag/burp/) - [prevent](https://tzusec.com/tag/prevent/) - [conditional access](https://tzusec.com/tag/conditional-access/) - [burp suite](https://tzusec.com/tag/burp-suite/) - [demo](https://tzusec.com/tag/demo/) - [youtube](https://tzusec.com/tag/youtube/) - [MFA](https://tzusec.com/tag/mfa/) - [Multi-factor authentication](https://tzusec.com/tag/multi-factor-authentication/) - [FIDO2](https://tzusec.com/tag/fido2/) - [systemctl](https://tzusec.com/tag/systemctl/) - [systemd](https://tzusec.com/tag/systemd/) - [gophish](https://tzusec.com/tag/gophish/) - [daemon-reload](https://tzusec.com/tag/daemon-reload/)