Submit your favorite resources for free.

Submit
HackDB logoHackDB
icon of Modlishka

Modlishka

Modlishka is a MITM proxy to bypass 2FA, enabling transparent multi-domain TLS traffic over a single domain without client certificates.

Introduction

Modlishka is a penetration testing tool functioning as a man-in-the-middle proxy. It transparently proxies multi-domain TLS/non-TLS traffic over a single domain, bypassing many 2FA implementations.

Key Features:

  • Universal 2FA Bypass: Supports a wide range of 2FA schemes.
  • Transparent Proxying: Proxies HTTP and HTTPS traffic without requiring client-side certificate installation.
  • Client Domain Hooking: Implements the Client Domain Hooking attack.
  • JavaScript Injection: Allows pattern-based JavaScript payload injection.
  • Stateless Design: Enables easy scaling for handling large traffic volumes.
  • Plugin Support: Extensible through modular plugins.

Use Cases:

  • Ethical phishing penetration tests.
  • Wrapping legacy websites with TLS.
  • Credential harvesting.
  • Web session impersonation.

Information

  • Publisher
  • Websitegithub.com
  • Created date08/07/2025
  • Published date08/07/2025
215+ Subscribers
Newsletter

Join 215+ Professionals

Receive our monthly newsletter featuring the latest additions to the directory.

No spam. Unsubscribe anytime.