Social media account hijacking — VDP

1 month ago 33
BOOK THIS SPACE FOR AD
ARTICLE AD

embossdotar

Link hijacking vulnerability. External link hijacking.

Already fixed vuln reported by me to Odoo Security Team (but not only about that!).

Hi,
Short intro, it is little bit about VDP from Odoo, more about the org you can find here.

After reading this article you should know about “Social media account hijacking” and connected, similar vulns.

Disclaimer: this writeup is for educational or ethical hacking purposes only. Don’t use it to harmful actions.

At the beginning of this article there is more about the vuln, at the end more about report from VDP (little spoiler: fixed, but no HoF).

What vulnerability can be the most dangerous? Perhaps the one which you can not fix.

Yeah, you see well — it can happen like that. I know the case of some well known bank (sic! what about those all regulations in bank sector?!) in my region, where they had TWO account taken over of social media — which they shows on own website… That’s the pity you didn’t see my face, after I click these links delivered by them (yup, I was really surprised). Accounts looked like totaly new, no content etc, but the same looked like some security researcher done previously a POC of ‘Social media account hijacking’ (some not harmful avatar from anime and short not harmful content).

Read Entire Article