Get a Pentest and security assessment of your IT network.

News

Path Encoding Vulnerability in https/www redirects.

302-based header injection can be really useful to leak?query data by putting them in the #fragment. Many web servers are configured in a way to redirect http://site.com/%23lol to http://www.site. They kill initial encoding, putting query data in locationhash.hash. And this is a vulnerability. There are just thousands of open-redirects out there leaking access_token-s. I personally found an open redirect leaking user’s token on 2 out of 3 huge websites i checked.”]

Source: http://homakov.blogspot.com/2014/01/path-encoding-vulnerability-in-httpswww.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Tracking wearable devices could be very easy via Bluetooth Low Energy

News

Social Networks Part 1 Who exactly are you disclosing your life story to?