Загрузка...

OAuth Misconfiguration Leading to Pre-Account Takeover | Bug Bounty PoC

In this video, I demonstrate how an OAuth account-linking misconfiguration can lead to a pre-account takeover scenario.

The issue occurs when an attacker pre-registers an account using a victim’s email address, then the victim later signs in using OAuth, such as Google login. If the application incorrectly links or merges the OAuth identity with the pre-existing account without properly invalidating the attacker-controlled credentials, the attacker may retain access to the victim’s account.

This video is intended for educational and responsible disclosure purposes only. The demonstration is performed in a controlled environment and focuses on helping developers, security engineers, and bug bounty hunters understand the risks of insecure OAuth account linking.

#BugBounty #OAuth #PreAccountTakeover #CyberSecurity #AppSec #WebSecurity #EthicalHacking #AccountTakeover #OAuthSecurity #HackerOne #BugBountyTips #AuthenticationSecurity #SecurityResearch #Pentesting #OvawatchSec

Видео OAuth Misconfiguration Leading to Pre-Account Takeover | Bug Bounty PoC канала ovawatch security
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять