• Security
  • By Sergiu Gatlan
  • September 10th, 2018
OAuth Exploit Allowed Researcher to Takeover Periscope TV Account

OAuth Exploit Allowed Researcher to Takeover Periscope TV Account

He hijacked the OAuth flow via host header poisoning

Google to Tighten OAuth Rules to Block Phishing Attempts After Fake Docs Attack

Google to Tighten OAuth Rules to Block Phishing Attempts After Fake Docs Attack

After last week's attack, Google will work to make Gmail even safer against phishing attacks by adding more rules

PayPal Fixes Security Flaw Allowing Hackers to Steal OAuth Tokens

PayPal Fixes Security Flaw Allowing Hackers to Steal OAuth Tokens

The bug was originally discovered in September

"Deploy on Heroku" Buttons Lead to Complete Pwnage of Heroku Accounts

"Deploy on Heroku" Buttons Lead to Complete Pwnage of Heroku Accounts

Heroku OAuth was leaking global API access token

OAuth Protocol Dodges a Bullet, Dangerous Flaws Fixed in Secret

OAuth Protocol Dodges a Bullet, Dangerous Flaws Fixed in Secret

Authentication protocol fixed for two critical issues

GNU MediaGoblin 0.8.1 Open-Source Media Server Fixes Critical OAuth Security Flaw

GNU MediaGoblin 0.8.1 Open-Source Media Server Fixes Critical OAuth Security Flaw

Available now for all GNU/Linux operating systems

Authentication Tokens Found in App Source Codes by the Thousands

Authentication Tokens Found in App Source Codes by the Thousands

Oftentimes secret keys are not obfuscated or protected in any way

“Covert Redirect” OAuth Security Flaw Not as Serious as It Sounds, Experts Say

“Covert Redirect” OAuth Security Flaw Not as Serious as It Sounds, Experts Say

User interaction is required and an open redirect must exist for the attack to work

OAuth Vulnerabilities Allowed Hackers to Access Private Photos on Instagram – Video

OAuth Vulnerabilities Allowed Hackers to Access Private Photos on Instagram – Video

Fortunately, Facebook has addressed the issues identified by Break Security

OAuth Flaw in Facebook Gives Researcher Full Control over Any Account – Video

OAuth Flaw in Facebook Gives Researcher Full Control over Any Account – Video

Facebook addressed the vulnerability after being notified by Nir Goldshlager

Google Adds OAuth 2.0 Support for Email and Chat Apps, Expanding 2-Step Verification

Google Adds OAuth 2.0 Support for Email and Chat Apps, Expanding 2-Step Verification

You won't need to provide a password for any email or chat client you use

Google's OAuth 2.0 Playground is for Skittish Developers

Google's OAuth 2.0 Playground is for Skittish Developers

It enables developers to play around with OAuth 2.0 and Google APIs without getting hurt

Twitter Forces Password Reset for Those Buying Followers

Twitter Forces Password Reset for Those Buying Followers

As their accounts may be in danger

 
Want more? Browse: