Tipos de estafa
OAuth-consent phishing
A hostile application asks for access through a real identity-provider screen.
Los artículos de investigación y las referencias se publican en inglés. La navegación está disponible en siete idiomas.
Personas y proyectos
En este artículo
Overview
A hostile application asks for access through a real identity-provider screen.
Why it matters
The password goes to the real provider, but the attacker receives mail, file or contact scopes.
What to check
Review application identity, redirect URI and permissions; preserve consent logs.