Masked Menace: How a Fake OAuth App and a Loose GraphQL Endpoint Stole the Real Keys

letslearngraphql

Masked Menace: How a Fake OAuth App and a Loose GraphQL Endpoint Stole the Real Keys

… GraphQL Endpoint Stole the Real Keys 安全专家在大规模侦察中发现隐藏于OAuth授权流程后的GraphQL端点,并利用工具识别出可疑子域名auth-api.target.com …

 

Read More