Collected research
Oh-Auth - Abusing OAuth to take over millions of accounts
Salt Labs Finds OAuth Abuse Used to Take Over Accounts
Sites that accept a social-login access token frequently never verify which application the token was minted for. An attacker who harvests Facebook tokens on an innocuous site of their own can replay them into Vidio, Bukalapak and Grammarly, the last by swapping the code parameter for access_token, and take over any victim's account there with no interaction from the victim.
Record
- Document
- Salt Labs Finds OAuth Abuse Used to Take Over Accounts
- Researcher
- Aviad Carmel
- Published by
- Salt Security
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Aviad Carmel, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .