Web Hack List

Other nomination

How We Broke Exchanges: A Deep Dive Into Authentication And Client-Side Bugs

Two authentication flaws found auditing exchanges and wallets. Allow-listing localhost as an OAuth origin lets a malicious mobile app run a local web server and complete sign-in silently to capture the token. Separately, a CORS policy allowing credentials from insecure subdomains lets a network attacker tamper with one and read the session token.

Record

Researcher
Bruno Halltari and Caue Obici
Published by
OtterSec
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Bruno Halltari and Caue Obici, first published at the original source. Preserved copies are kept so the citation survives its host.