Web Hack List

Collected research

OAuth Security Advisory 2009.1: OAuth 1.0 Request Token Session Fixation

OAuth Security Advisory 2009.1 — OAuth

A session fixation flaw in the OAuth 1.0 three-legged authorization flow. The attacker starts the flow at an honest consumer, saves the authorization URI containing his own Request Token, and lures a victim into clicking it; once the victim approves at the legitimate service provider, the attacker completes the flow with the saved token. Fixed by OAuth Core 1.0 Revision A.

Record

Document
OAuth Security Advisory 2009.1 — OAuth
Published by
oauth.net
Format
Advisory
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of oauth.net, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .