What is a fake login page?¶
A fake login page imitates a genuine service so that the victim will enter credentials, codes or other sensitive information.
The visual appearance is often the least interesting part. Logos, colours and wording are easy to copy.
The useful evidence is in the URL, infrastructure, page behaviour and where submitted data goes.
Look beyond the screenshot¶
A fake page investigation may involve:
- domain name;
- URL path;
- hosting;
- certificate;
- HTML/form behaviour;
- submission endpoint;
- redirects;
- page capture;
- time the site was live.
A page may look exactly like Microsoft 365 while sitting on unrelated infrastructure.
Some fake pages relay to the real service¶
A victim may enter credentials into the fake page, which then passes them on to the genuine service.
That can make the interaction look plausible to the victim while exposing the submitted information or session material.
The technical route might be:
Preserve before interacting¶
Where possible, preserve:
- original link;
- page capture;
- page source where authorised;
- hosting/domain information;
- submission endpoint;
- time and context.
Do not enter genuine credentials into the page simply to see what happens.
Visit, submission and later use are separate¶
The victim may visit without submitting.
They may submit data that never reaches the attacker.
The attacker may receive it but never use it.
So build the stages separately.
What is credential harvesting? explains the collection stage.
The practical point is: prove the fake page from its infrastructure and data flow. Then establish visit, submission, receipt and later account use as separate events.