Web Hack List

Top 10 winner

Account hijacking using "dirty dancing" in sign-in OAuth-flows

Deliberately breaking an OAuth sign-in flow - an invalid state, a switched response type, a tampered redirect_uri - leaves the code or token in the victim's URL on an error page. The attacker then reads that URL via a third-party gadget already on the page, such as a lax postMessage listener, an XSS-able sandbox iframe, a storage iframe or a chat widget API, and hijacks the account in one click.

Record

Researcher
Frans Rosén
Published by
Labs Detectify
Date
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Frans Rosén, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .