Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities Notes #5

Open
joydo opened this issue Jun 2, 2022 · 0 comments
Open

Vulnerabilities Notes #5

joydo opened this issue Jun 2, 2022 · 0 comments
Labels

Comments

@joydo
Copy link
Owner

joydo commented Jun 2, 2022

Account Pre-Hijacking

  • the hackers signs up with [email protected] via the normal email/pass way

  • the email arrives in xxxx their mailbox but it is ignored (might even be flagged as something they don’t read anyway because, for now, it’s an unknown service)

  • the user, at some time in the future, goes to the site and signs up (they think) by clicking ‘sign up with Google’

  • the site now merges the former account with the latter and signs in the user; because signing in with gmail, there is no email link that has to be clicked

The site’s ( erroneous ) db entry is now a validated (via sso) account with a manual password; the hacker can now login with the password they set in the first place while the real user logs in via the Google sso link.

@joydo joydo added the Vulns label Jun 2, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant