Web Hack List

Later archive addition

OAuth Security Advisory 2009.1: OAuth 1.0 Request Token Session Fixation

A session fixation flaw in the OAuth 1.0 three-legged authorization flow. The attacker starts the flow at an honest consumer, saves the authorization URI containing his own Request Token, and lures a victim into clicking it; once the victim approves at the legitimate service provider, the attacker completes the flow with the saved token. Fixed by OAuth Core 1.0 Revision A.

Record

Format
Advisory

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.