Welcome guest, is this your first visit? Create Account now to join.
  • Login:

Members in Chat:
+ Reply to Thread
Results 1 to 1 of 1
  1. #1
    Will.Spencer's Avatar
    Will.Spencer is online now Skipper Recent Blog: Daily News Montenegro
    Join Date
    Dec 2008
    Location
    Singapore
    Posts
    6,356
    $NetBucks
    21,113
    Blog Entries
    1
    Thanked 2,295 Times in 1,244 Posts

    OAuth Vulnerability Opens Google Customer Data to Attack

    A newly discovered OAuth Session Fixation Attack creates problems for every organization which uses OAuth, including Google.

    According to Using OAuth with the Google Data APIs:
    Recently, all of the Google Data APIs adopted support for OAuth, an open protocol that aims to standardize the way desktop and web applications access a user's private data.
    Looks for fairly sophisticated phishing attacks to start appearing in the near future.

    But these new phishing attacks won't be as easy to spot as the phishing attacks that we're trained ourselves to ignore.

    Quoting from the vulnerability explanation:
    The attacker then uses social engineering to trick a victim into following that link (the authorization URI from the redirection). This can be as simple as a blog post with a review of the application, inviting people to try it out. When someone clicks on that link, they are sent to the provider to authorize access.

    Since this is what he wanted to do, the victim will not realize that he should have started at the application itself, and will continue to sign into the provider. Because of how we train people to look for phishing attacks, even an educated user will notice that he is at the right place.

    The provider will then ask the user to grant access, identifying the right application. This will increase the comfort level of the user, since so far, everything checks out.
    Submit Your Webmaster Related Sites to the NB Directory
    I swear, by my life and my love of it, that I will never live for the sake of another man, nor ask another man to live for mine.


 

Similar Threads

  1. Google and Bing Using Twitter Data for Rankings
    By Will.Spencer in forum Social Networks
    Replies: 10
    Last Post: 1 February, 2012, 08:19 AM
  2. Replies: 3
    Last Post: 13 June, 2010, 18:45 PM
  3. Replies: 2
    Last Post: 7 August, 2009, 18:00 PM
  4. Replies: 2
    Last Post: 24 May, 2009, 21:20 PM
  5. SMF serious vulnerability [!!!]
    By Hellas in forum Managing
    Replies: 0
    Last Post: 20 May, 2009, 22:52 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts