Logótipo oficial do MASTR MASTR Apoiar o trabalho
Índice
← Início da wiki

Tipos de fraude

OAuth-consent phishing

A hostile application asks for access through a real identity-provider screen.

Reference note · Sources below

Os artigos de investigação e as referências são publicados em inglês. A navegação está disponível em sete idiomas.

Pessoas e projetos

Neste artigo
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

A hostile application asks for access through a real identity-provider screen.

Why it matters

The password goes to the real provider, but the attacker receives mail, file or contact scopes.

What to check

Review application identity, redirect URI and permissions; preserve consent logs.

Sources

Leituras relacionadas

Tipos de fraude

Permit phishing

An offchain signature authorises a token allowance without an immediate gas payment.

MASTR

Apoiar a investigação independente

As investigações, as provas originais e os guias são de acesso livre. Os donativos voluntários ajudam a financiar a investigação e a manter disponíveis as ferramentas MASTR.

Abrir carteira