• Security
  • By Catalin Cimpanu
  • January 11th, 2016
CSRF Bug in Verizon's API Left My FiOS Accounts Open to Attacks

CSRF Bug in Verizon's API Left My FiOS Accounts Open to Attacks

API used a simple authentication scheme, exposing users to CSRF attacks that allowed third-parties to hijack accounts

Verizon’s My FiOS for Android Allowed Complete Access to Email Accounts

Verizon’s My FiOS for Android Allowed Complete Access to Email Accounts

Attacker could send messages from a different user's address