4 ms·
> But this seems to require access to a different oauth token already The article explans quite well how that works. The attacker makes an outwardly legitimate
by usrbinbash 3y ago
> But this seems to require access to a different oauth token already
The article explans quite well how that works. The attacker makes an outwardly legitimate service, which is registered at the OAuth authentication provider, and waits for people to access it. All it has to do, is store the tokens on its backend, and try them, with the same username, against other services, using the same auth provider.