Types d’arnaques
OAuth-consent phishing
A hostile application asks for access through a real identity-provider screen.
Les enquêtes et les fiches de référence sont publiées en anglais. La navigation est disponible en sept langues.
Personnes et projets
Dans cet article
Overview
A hostile application asks for access through a real identity-provider screen.
Why it matters
The password goes to the real provider, but the attacker receives mail, file or contact scopes.
What to check
Review application identity, redirect URI and permissions; preserve consent logs.