官方的 MASTR 标志 MASTR 支持这项工作
目录
← 知识库首页

诈骗模式

OAuth-consent phishing

A hostile application asks for access through a real identity-provider screen.

Reference note · Sources below

研究文章和参考条目以英语发布。导航提供七种语言。

人物与项目

本文目录
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

A hostile application asks for access through a real identity-provider screen.

Why it matters

The password goes to the real provider, but the attacker receives mail, file or contact scopes.

What to check

Review application identity, redirect URI and permissions; preserve consent logs.

Sources

相关阅读

诈骗模式

Permit phishing

An offchain signature authorises a token allowance without an immediate gas payment.

MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包