诈骗模式
OAuth-consent phishing
A hostile application asks for access through a real identity-provider screen.
研究文章和参考条目以英语发布。导航提供七种语言。
人物与项目
Overview
A hostile application asks for access through a real identity-provider screen.
Why it matters
The password goes to the real provider, but the attacker receives mail, file or contact scopes.
What to check
Review application identity, redirect URI and permissions; preserve consent logs.