Web Hack List

Other nomination

Oh-Auth - Abusing OAuth to take over millions of accounts

Sites that accept a social-login access token frequently never verify which application the token was minted for. An attacker who harvests Facebook tokens on an innocuous site of their own can replay them into Vidio, Bukalapak and Grammarly, the last by swapping the code parameter for access_token, and take over any victim's account there with no interaction from the victim.

Record

Researcher
Aviad Carmel
Published by
Salt Security

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aviad Carmel, first published at the original source. Preserved copies are kept so the citation survives its host.