Published Vulnerabilities

Mon
05
Aug

Microsoft Yammer – OAuth Bypass & Token Vulnerability

Microsoft Yammer – OAuth Bypass & Token Vulnerability

At 2013-07-31 we got the info mail of the microsoft security response center regarding a submission of july. The advisory and security vulnerability report has been written by Ateeq Khan a new member of the vulnerability laboratory core research team. Ateeq's location is pakistan and he is a well known security researcher and penetration tester. The vulnerability report of Ateeq Khan is about a new remote oauth bypass vulnerability in the microsoft yammer social network online-service web application.

Sun
28
Jul

Facebook Bug Bounty 2013 – Open Redirect Vulnerability

Facebook Bug Bounty 2013 – Open Redirect Vulnerability

A open redirect and filter bypass vulnerability was detected in the official original Facebook and Facebook core application. The vulnerability allows to bypass the basic validation of the application module to redirect users unauthorized to an external source.

Normally the redirect exception only allows the attacker to redirect to allowed or internal applications. The attacker exchanges the application url id with a valid request and can inject an url to external target but the attacker needs to make at the end of the domain a bind.php#_=_ to redirect successful to the external source. After requesting the url which does not expire because of the client id which can be exchanged randomly with others the request will redirect the victim to another web page.

Pages

Subscribe to RSS - Published Vulnerabilities