OAUTH Misconfiguration - OAUTH
Hello Team,
Description:
OAuth is a functionality used by a user for easy sign-up or login on your domain. In this account, the attacker can easily control the victim’s account if the victim uses OAUTH functionality.
Replication Steps:
- Make an account with the victim’s email address and set a password.
- Now you have access to the victim’s account through a password and email id.
- The victim will create an account through google OAuth functionality.
- Thus, the victim is not required to set a password.
- You can access the victim's account through a password you set in the attacker phase.
- So, you can use a victim account whenever you want!
(ATTACKER PHASE)
(VICTIM COMES )
(EXPLOIT)
MITIGATION:
Thank you