Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
我们如何攻破交易所:认证与客户端漏洞深度剖析
osec.io
| 研究 |
#web3
|
#account-takeover
|
#authentication
|
#vulnerability
|
#oauth
|
#exchanges
摘要
OtterSec 剖析交易所、SDK 与钱包中的 OAuth 错误配置:从 Google GSI/FedCM 流程细节到桌面与移动环境差异,揭示常见开发设置如何导致账户接管。
发布时间
2025-10-16 12:00
收录时间
2026-07-31 01:54
原文 ↗
相关内容
在 Web3 中颠覆 Web2 认证
(osec.io)
将用户身份从 AI 代理传播到您的工具:Amazon Bedrock AgentCore Gateway 和 JFrog Artifactory
(jfrog.com)
OAuth 2.0 Client Credentials Misuse in Public Apps
(blog.sentry.security)
Permanent account takeover on Yahoo's Small Business platform
(samcurry.net)
检测 Web 消息配置错误以防范跨域凭据窃取
(portswigger.net)
隐藏的 OAuth 攻击向量
(portswigger.net)
返回