Almost two years after pointing out a public key vulnerability to GitHub, security researcher Egor Homakov has focused his attention on the service’s OAuth implementation.
Almost two years after pointing out a public key vulnerability to GitHub, security researcher Egor Homakov has focused his attention on the service’s OAuth implementation.
Now that GitHub has launched a bug bounty program, many security researchers are taking a crack at the code repository. One of them is Egor Homakov, who has managed to gain access to private GitHub repositories by using a combination of 5 low-severity flaws. Separately, the 5 vulnerabilities cant be exploited to cause too much […]
Security researcher Egor Homakov has identified a couple of vulnerabilities that can be exploited to hijack accounts on websites that allow users to authenticate by using their Facebook accounts. Unfortunately, Facebook will not address these issues any time soon. The first security hole, a CRSF on Facebook.com, can be leveraged by cybercriminals to hijack accounts […]
Latest Comments