Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Why 2FA would not have saved HT?

Summary

A trivial SQL injection in yubico-yubiserve, a Python YubiKey OTP server: an unfiltered publicID parameter in the OATH path lets attackers run SQL; the flaw is in the server, not the hardware.
Published
Collected

original ↗

Related coverage

back