Logo video2dn
  • Сохранить видео с ютуба
  • Категории
    • Музыка
    • Кино и Анимация
    • Автомобили
    • Животные
    • Спорт
    • Путешествия
    • Игры
    • Люди и Блоги
    • Юмор
    • Развлечения
    • Новости и Политика
    • Howto и Стиль
    • Diy своими руками
    • Образование
    • Наука и Технологии
    • Некоммерческие Организации
  • О сайте

Скачать или смотреть Open Redirect Flaw Snags Amex, Snapchat User Data | Hacker News

  • CSI digital
  • 2022-08-11
  • 66
Open Redirect Flaw Snags Amex, Snapchat User Data | Hacker News
advisorythreatcybersecuritysecurityproviderredirectionrecipientsurlredirect flawurl redirect attackurl redirection attackCWE-601
  • ok logo

Скачать Open Redirect Flaw Snags Amex, Snapchat User Data | Hacker News бесплатно в качестве 4к (2к / 1080p)

У нас вы можете скачать бесплатно Open Redirect Flaw Snags Amex, Snapchat User Data | Hacker News или посмотреть видео с ютуба в максимальном доступном качестве.

Для скачивания выберите вариант из формы ниже:

  • Информация по загрузке:

Cкачать музыку Open Redirect Flaw Snags Amex, Snapchat User Data | Hacker News бесплатно в формате MP3:

Если иконки загрузки не отобразились, ПОЖАЛУЙСТА, НАЖМИТЕ ЗДЕСЬ или обновите страницу
Если у вас возникли трудности с загрузкой, пожалуйста, свяжитесь с нами по контактам, указанным в нижней части страницы.
Спасибо за использование сервиса video2dn.com

Описание к видео Open Redirect Flaw Snags Amex, Snapchat User Data | Hacker News

Attackers are exploiting a well-known open redirect flaw to phish people?s credentials and personally identifiable information (PII) using American Express and Snapchat domains, researchers have found.
Threat actors impersonated Microsoft and FedEx among other brands in two different campaigns, which researchers from INKY observed from mid-May through late July, they said in a blog post published online. Attackers took advantage of redirect vulnerabilities affecting American Express and Snapchat domains, the former of which eventually was patched while the latter still is not, researchers said. Open redirect is a security vulnerability that occurs when a website fails to validate user input, which allows bad actors to manipulate the URLs of domains from legitimate entities with good reputations to redirect victims to malicious sites, researchers said. The vulnerability is well known and tracked as CWE-601: URL Redirection to Untrusted Site (?Open Redirect?).
?Since the first domain name in the manipulated link is in fact the original site?s, the link may appear safe to the casual observer,? INKY?s Roger Kay explained in the post.
An example of the malicious redirect domain is: http[://]safe[.]com/redirect?[url=http:]//malicious[.]com. The trusted domain, then?in this case, American Express or Snapchat?is used as a temporary landing page before the victim of the campaign is redirected to a malicious site.
During the two-and-a-half-month period over which the campaigns were observed, researchers detected the snapchat[.]com open redirect vulnerability in 6,812 phishing emails originating from various hijacked accounts, they said. Meanwhile, over just two days in late July, they observed the americanexpress[.]com open redirect vulnerability in 2,029 phishing emails that originated from newly created domains.
Both campaigns started with phishing emails using typical social-engineering tactics to try to trick users into clicking on malicious links or attachments, researchers said.
The two campaigns also both used exploits in which attackers inserted PII in the seemingly legitimate URL so that the malicious landing pages could be customized on the fly for the individual victims, they said.
This insertion was disguised by converting it to Base 64 to make it look like a bunch of random characters,? Kay wrote. ?We inserted our own random characters into these strings so that the casual observer would not be able to reverse engineer the PII strings.?
When being redirected to another site, victims would think the link was heading somewhere safe; however unbeknownst to them, the domains to which they were being redirected were malicious sites to harvest their credentials or expose them to malware, researchers said.

#redirection #recipients #url #advisory #threat #cybersecurity #security

Комментарии

Информация по комментариям в разработке

Похожие видео

  • О нас
  • Контакты
  • Отказ от ответственности - Disclaimer
  • Условия использования сайта - TOS
  • Политика конфиденциальности

video2dn Copyright © 2023 - 2025

Контакты для правообладателей [email protected]