设备代码钓鱼:技术分析与基于 Netlas 的主动追踪
netlas.io | 研究 | #threat-hunting | #phishing | #oauth | #token-theft | #netlas | #device-code-phishing
摘要
设备代码钓鱼技术分析:滥用 OAuth 2.0 设备授权流程(RFC 8628),受害者在真实微软页面输入代码、令牌却落入攻击者手中;文章对比多类钓鱼模板并给出 Netlas 追踪方法。
- 发布时间
- 收录时间
Skip to content