ijeff@lemdro.idM to Android@lemdro.idEnglish · 11 months agoMalware abuses Google OAuth endpoint to ‘revive’ cookies, hijack accountswww.bleepingcomputer.comexternal-linkmessage-square4fedilinkarrow-up192arrow-down13cross-posted to: hackernews@derp.foo
arrow-up189arrow-down1external-linkMalware abuses Google OAuth endpoint to ‘revive’ cookies, hijack accountswww.bleepingcomputer.comijeff@lemdro.idM to Android@lemdro.idEnglish · 11 months agomessage-square4fedilinkcross-posted to: hackernews@derp.foo
minus-squareepyon22@programming.devlinkfedilinkEnglisharrow-up4·11 months agoIt’s based on security hole in what I’m interpreting as a web API. You leverage a legitimatly logged in Google account on a malicious website and this web endpoint gives you keys to everything else
It’s based on security hole in what I’m interpreting as a web API. You leverage a legitimatly logged in Google account on a malicious website and this web endpoint gives you keys to everything else