Web Hack List

Collected research

Oh-Auth - Abusing OAuth to take over millions of accounts

Salt Labs Finds OAuth Abuse Used to Take Over Accounts

Sites that accept a social-login access token frequently never verify which application the token was minted for. An attacker who harvests Facebook tokens on an innocuous site of their own can replay them into Vidio, Bukalapak and Grammarly, the last by swapping the code parameter for access_token, and take over any victim's account there with no interaction from the victim.

Record

Document
Salt Labs Finds OAuth Abuse Used to Take Over Accounts
Researcher
Aviad Carmel
Published by
Salt Security
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aviad Carmel, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .