Top 10 winner
Account hijacking using "dirty dancing" in sign-in OAuth-flows
Deliberately breaking an OAuth sign-in flow - an invalid state, a switched response type, a tampered redirect_uri - leaves the code or token in the victim's URL on an error page. The attacker then reads that URL via a third-party gadget already on the page, such as a lax postMessage listener, an XSS-able sandbox iframe, a storage iframe or a chat widget API, and hijacks the account in one click.
Record
- Researcher
- Frans Rosén
- Published by
- Labs Detectify
- Date
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Frans Rosén, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .