Why 2FA would not have saved HT?
blog.quarkslab.com | research | #sql-injection | #authentication | #python | #vulnerability | #2fa | #yubikey
Summary
A trivial SQL injection in yubico-yubiserve, a Python YubiKey OTP server: an unfiltered publicID parameter in the OATH path lets attackers run SQL; the flaw is in the server, not the hardware.
- Published
- Collected
Skip to content