Web Hack List

Collected research

An analysis of logic flaws in web-of-trust services

Web-of-trust services such as Keybase verify identity by scraping a token from a page the user controls. Three logic flaws break that: a gist the victim forks carries the attacker's token under the victim's name, a site allowing dots in usernames lets an attacker publish keybase.txt at its root, and a redirect-following scraper credits the wrong domain, each giving identity takeover.

Record

Researcher
EdOverflow and @EdOverflow
Published by
EdOverflow
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of EdOverflow and @EdOverflow, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .