3 ms·
Just generic spoofing. Like you pointed out watching for google.com.evil instead of google.com, and theres also email phishing where they try to replicate a com
by eks391 4y ago
Just generic spoofing. Like you pointed out watching for google.com.evil instead of google.com, and theres also email phishing where they try to replicate a companies email and get you to click links, etc. Theres so many ways to spoof things, and I can't imagine it being impossible to spoof oAuth. It wouldn't affect people with 2FA enabled, but for the majority of users with poor security practices or are not tech-savy it would do harm.
Just off the top of my head I can think of one possible way: Send an email pretending to be a popular company, with some excuse to need an oAuth (like "Your oAuth for ImportantApp is expiring, please renew access. Act fast so you don't lose access to ImportantFeature!" Or "Our policies are changing. Please confirm oAuth to authenticate your acceptance to continue using ImportantApp") It doesnt need to be fancy, just enough to fool people who don't know that oAuth is not relevant to the email. Then they click a link in the spoofed email to the host server, with a spoofed copy of the target website. oAuth isnt going to suggest the credentials because the url is wrong, so don't ask for the credentials to the target website. Instead ask them to verify access of the website on your fake oAuth, then to confirm your decision with their gmail password. Then say it worked and redirect them to the real site. You already have their email, but now their email password as well. Automate this with bots, and then you have tons of peoples 2FA, since most peoples 2FA for website log ins is their email. Next you just do the "I forgot my username" which always asks for an associated email. Then "I forgot my password" which, on unsecure sites, also uses the email. Boom. Free accounts.
Obviously there are ways to secure yourself from any basic attack like the one I just described, but for the general public that trusts tech to be flawless without their concerted effort, traps are just a matter of someone with time and motivation to make them. No trap is flawless, but there are enough people for that to not matter.