Wednesday, December 18, 2024
HomeCyber Security NewsHackers Abusing OAuth Token to Take Over Millions of Accounts

Hackers Abusing OAuth Token to Take Over Millions of Accounts

Published on

SIEM as a Service

A new OAuth vulnerability has been discovered in three of the major extensions such as Grammarly, Vidio, and Bukalapak. These applications use the OAuth protocol for their authentication, which is vulnerable to an authentication token-stealing attack.

OAuth is an authentication protocol that was introduced in 2006 and acts as a passwordless signing-in for many applications through social media accounts such as Facebook, Twitter, or Google.

This particular flaw could affect millions of users as all of these affected vendors have combined to have more than 100M users. However, all of the affected vendors acted swiftly upon the reported issues and fixed them accordingly.

- Advertisement - SIEM as a Service

Account TakeOver Due to Lack of Token Validation

If an application has implemented OAuth authentication for its users, the application must validate if the authentication token is from a legitimate vendor or a malicious token.

In such a case, if the applications do not validate the token, threat actors can create a malicious website and insert their token from Facebook or Google to hijack the user’s account on the affected application.

Moreover, threat actors can lure multiple victims and perform massive account hijacking if the website has a great reputation.

For demonstration purposes, researchers created a malicious website with Facebook developers and gained an OAuth authentication token for their application.

OAuth massive account hijack (Source: Salt Security)
OAuth massive account hijack (Source: Salt Security)

Furthermore, they replaced this token with this vulnerable application’s authentication token, which resulted in an account hijack.

It was also mentioned that these were just sample applications, and there are still thousands of applications that lack this token validation and are vulnerable to massive account hijacks.

A complete report about this attack has been published by Salt Security, which provides detailed information about the attack, source code, mechanism, and other information.

It is recommended that developers implement a token validation for OAuth tokens to prevent this kind of exploitation by threat actors.

Protect yourself from vulnerabilities using Patch Manager Plus to patch over 850 third-party applications quickly. Try a free trial to ensure 100% security.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Cyber Criminals Exploit Windows Management Console to Deliver Backdoor Payloads

A recent campaign dubbed FLUX#CONSOLE has come to light, leveraging Microsoft Common Console Document (.MSC) files...

Texas Tech Systems Breach, Hackers Accessed System Folders & Files

The Texas Tech University Health Sciences Center (TTUHSC) and Texas Tech University Health Sciences...

Beware of Malicious Ads on Captcha Pages that Deliver Password Stealers

Malicious actors have taken cybercrime to new heights by exploiting captcha verification pages, a...

Hitachi Authentication Bypass Vulnerability Allows Attackers to Hack the System Remotely

Critical Authentication Bypass Vulnerability Identified in Hitachi Infrastructure Analytics Advisor and Ops Center Analyzer.A...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Cyber Criminals Exploit Windows Management Console to Deliver Backdoor Payloads

A recent campaign dubbed FLUX#CONSOLE has come to light, leveraging Microsoft Common Console Document (.MSC) files...

Texas Tech Systems Breach, Hackers Accessed System Folders & Files

The Texas Tech University Health Sciences Center (TTUHSC) and Texas Tech University Health Sciences...

Beware of Malicious Ads on Captcha Pages that Deliver Password Stealers

Malicious actors have taken cybercrime to new heights by exploiting captcha verification pages, a...