Other nomination
#317476 Account Takeover in Periscope TV
Periscope's Twitter OAuth login echoed the Host header into its redirect target, so a request carrying Host set to attacker.com/www.periscope.tv sent the OAuth callback to the attacker. A victim who authorises the resulting link hands over their oauth verifier, letting the attacker finish the flow and take over the Periscope account.
Record
- Researcher
- Ron Chan
- Published by
- HackerOne
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Ron Chan, first published at the original source. Preserved copies are kept so the citation survives its host.