Other nomination
Oh-Auth - Abusing OAuth to take over millions of accounts
Sites that accept a social-login access token frequently never verify which application the token was minted for. An attacker who harvests Facebook tokens on an innocuous site of their own can replay them into Vidio, Bukalapak and Grammarly, the last by swapping the code parameter for access_token, and take over any victim's account there with no interaction from the victim.
Record
- Researcher
- Aviad Carmel
- Published by
- Salt Security
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Aviad Carmel, first published at the original source. Preserved copies are kept so the citation survives its host.