An Adversary-in-the-Middle tool (Modlishka, Muraena, or Evilginx) sits between the browser and this origin. The user sees a login that looks like yours; the proxy forwards traffic and harvests credentials + session cookies.
…
…
…
Default password for seed accounts: LabPass!2026
Browser ──TLS──► hespera.org (this web-app)
│ POST /lab/api/login
│ Set-Cookie: session, sid, auth
▼
capture JSON ──► ops panel /admin sessions
▲
optional AiTM proxy would sit on the first hop