Tipos de fraude
OAuth-consent phishing
A hostile application asks for access through a real identity-provider screen.
Os artigos de investigação e as referências são publicados em inglês. A navegação está disponível em sete idiomas.
Pessoas e projetos
Neste artigo
Overview
A hostile application asks for access through a real identity-provider screen.
Why it matters
The password goes to the real provider, but the attacker receives mail, file or contact scopes.
What to check
Review application identity, redirect URI and permissions; preserve consent logs.