Potential security issues with OAuth were questioned after a researcher discovered a vulnerability on Periscope’s Twitter app, which could enable the takeover of users’ accounts.
Publishing his findings on HackerOne, Ron Chan said logging into Periscope TV through Twitter was susceptible to a host header attack that could result in a victim’s credentials being stolen.
Host header attacks are used for password reset or cache poisoning because they require an out of band attack channel. Chan discovered that he could use Periscope’s OAuth system as such a channel, provided his victim has accounts.
Ron Chan added that after changing the host header, an attacker is able to send the OAuth authorization link to their victim and obtain the user’s account details via the token that is issued.
The Paypers is the Netherlands-based leading independent source of news and intelligence for professional in the global payment community.
The Paypers provides a wide range of news and analysis products aimed at keeping the ecommerce, fintech, and payment professionals informed about the latest developments in the industry.
Current themes
No part of this site can be reproduced without explicit permission of The Paypers (v2.7).
Privacy Policy / Cookie Statement
Copyright