Collected research
Password Not Provided - Compromising Any Flurry Users Account
Password Not Provided - Compromising Any Flurry User's Account [Yahoo Bug Bounty]
Flurry's signup flow for accounts linked to a Yahoo login submitted the literal string not-provided as the password, and the ordinary login form accepted it. Anyone could sign in to any Yahoo-linked Flurry account using that user's email address and the password not-provided, reaching the analytics and ad accounts behind hundreds of thousands of apps.
Record
- Document
- Password Not Provided - Compromising Any Flurry User's Account [Yahoo Bug Bounty]
- Researcher
- Jack Cable
- Published by
- lightningsecurity.io
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Jack Cable, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .