Logo Oficial MASTR MASTR Apoyar el trabajo
Contenido
← Inicio de la wiki

Tipos de estafa

OAuth-consent phishing

A hostile application asks for access through a real identity-provider screen.

Reference note · Sources below

Los artículos de investigación y las referencias se publican en inglés. La navegación está disponible en siete idiomas.

Personas y proyectos

En este artículo
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

A hostile application asks for access through a real identity-provider screen.

Why it matters

The password goes to the real provider, but the attacker receives mail, file or contact scopes.

What to check

Review application identity, redirect URI and permissions; preserve consent logs.

Sources

Lecturas relacionadas

Tipos de estafa

Permit phishing

An offchain signature authorises a token allowance without an immediate gas payment.

MASTR

Apoya la investigación independiente

Las investigaciones, las pruebas originales y las guías son de acceso libre. Las donaciones voluntarias ayudan a financiar la investigación y a mantener disponibles las herramientas de MASTR.

Abrir billetera