3 ms·
Researchers took over Booking.com accounts using a legitimate Facebook link
The vulnerability exists in OAuth (social sign-in), used by almost every website today.
If you are unfamiliar with OAuth, the post (in the first comment) explains it step-by-step with detailed diagrams.
- aviCC 4y agohttps://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com https://salt.security/blog/traveling-with-oauth-account-take... Video: https://youtu.be/IK_AV1UFS-0 https://youtu.be/IK_AV1UFS-0