Twitter OAuth feature can be abused to hijack accounts, researcher says

JMH

Emeritus, Contributor
Joined
Apr 2, 2012
Posts
7,197
A feature in the Twitter API (application programming interface) can be abused by attackers to launch credible social engineering attacks that would give them a high chance of hijacking user accounts, a mobile application developer revealed Wednesday at the Hack in the Box security conference in Amsterdam.

The issue has to do with how Twitter uses the OAuth standard to authorize third-party apps, including desktop or mobile Twitter clients, to interact with user accounts through its API, Nicolas Seriot, a mobile applications developer and project manager at Swissquote Bank in Switzerland, said Thursday.
https://www.infoworld.com/d/securit...ts-researcher-says-216332?source=rss_security
 
Back
Top