We’ve all been there as ethical hackers: We are provided credentials for multiple accounts, with complex passwords and multi-factor authentication (MFA) to test our customers’ environments. While that is a great sign of authentication security best practices, it creates an annoyance for pentesters. There are different ways to make it easier such as temporarily using a password manager in the testing browser which supports MFA. But what if you are not using a browser for testing?
efkay•6h ago