|
|
|
|
|
by michaelt
3449 days ago
|
|
1. You visit the attacker's page and give them your username and password. 2. The attacker immediately tries them, triggering an SMS to you and an 'enter SMS code' page for them. 3. The attacker shows the 'enter SMS code' page to you, and you enter the code from the SMS you just received, giving it to the attacker. 4. The attacker completes their login using the SMS code. 5. The attacker shows the user some believable error message (implying an error on Google's end, or a typo in the SMS code) then forwards the user to the legitimate Google login page. |
|