Get a Pentest and security assessment of your IT network.

News

A critical Improper Authentication vulnerability in Uber allowed password reset for any account

Italian expert Vincenzo C. Aka @Procode701 has discovered a critical Improper Authentication vulnerability affecting the UBER platform that allowed password reset for any account. The Italian expert discovered a serious problem in the password reset process that could be exploited to generate an authentication token inAuthSessionID That could be used to change the password using the standard link that is present in the change password form. The Uber platform was generating a specific session token every time a user was sending password reset email. The impact of the vulnerability is severe, it allowed a hacker to access any account and any user’s data.”]

Source: https://securityaffairs.co/wordpress/59210/hacking/uber-improper-authentication.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Who and why is attacking companies in the Nordic Countries?

News

Social Networks Part 1 Who exactly are you disclosing your life story to?