The Accidental Discovery of a New Vulnerability in Google's OAuth Implementation

  Переглядів 36,154

Black Hat

Black Hat

2 місяці тому

Beware, dear friends, the cautionary tale of the cloud provider that broke its own security model. Ignoring RFCs! Putting plaintext passwords in scripts - and printing them in books! It's a crazy story, but one that may nonetheless resonate with enterprise security practitioners everywhere.
In early 2021, I identified a client impersonation vulnerability in a series of Google "first-party" applications. This vulnerability allows an attacker to present themselves both to a user and to Google as one of these applications, and enjoy all the privileges therein....
By: Brian Smith-Sweeney
Full Abstract and Presentation Materials: www.blackhat.com/us-23/briefi...

КОМЕНТАРІ
Has Generative AI Already Peaked? - Computerphile
12:48
Computerphile
Переглядів 251 тис.
ОДИН ДОМА #shorts
00:34
Паша Осадчий
Переглядів 5 млн
So You Think You Know Git - FOSDEM 2024
47:00
GitButler
Переглядів 905 тис.
A Decade After Stuxnet: How Siemens S7 is Still an Attacker's Heaven
38:32
Something Rotten in the State of Data Centers
40:27
Black Hat
Переглядів 8 тис.
hacker:HUNTER - Wannacry: The Marcus Hutchins Story - All 3 Chapters
25:11
Tomorrow Unlocked
Переглядів 1,7 млн
DON'T Use Raspberry Pis for Servers! (Use THIS)
16:23
Hardware Haven
Переглядів 965 тис.
Zero Trust Explained | Real World Example
21:46
CertBros
Переглядів 12 тис.
How to Smuggle Data out of the Network with Ping
16:54
Plaintext Packets
Переглядів 112 тис.
Wait... PostgreSQL can do WHAT?
20:33
The Art Of The Terminal
Переглядів 182 тис.