The attack demo against Facebook SSO
Sign in to YouTube
Sign in with your Google Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to like mountmic's video.
Sign in to YouTube
Sign in with your Google Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to dislike mountmic's video.
Sign in to YouTube
Sign in with your Google Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to add mountmic's video to your playlist.
Published on Mar 6, 2012
No description available.
-
Category
-
License
Standard YouTube License
Loading...
Loading...
Loading...
Loading...
Ratings have been disabled for this video.
Rating is available when the video has been rented.
This feature is not available right now. Please try again later.
Loading...
-
9:32
closing (trimmed-3)by KarenSKWC
357 views
-
4:42
Gmail, Facebook And Twitter Are Vulnerable. Other Users Can See When You are Logged Inby keithdsouza
1,016 views
-
3:55
SSO Howling Cave 4 Hackby Nobita Nobi
76 views
-
6:15
Facebook Nation pt 1 (The Best Times, June 2009)by WKNOPBS
165 views
-
3:06
Facebook Vulnerability - Destory Advertisementsby Ben Hayak
274 views
-
6:44
Demostrative Videoby Shilo Mendigo
8 views
-
4:54
Yaburi Sudden Attack Br Demoby Henrique Mendes
41 views
-
1:42
SSO demoby Katherine Bradley
2 views
-
1:26
Fingerboard demoby asa3166
99 views
-
1:22
Facebook Token Hijacker: Delete Facebook Token Hijackerby robert louis
15 views
-
3:01
Gathering Twitter Email.mp4by Sumate jitpukdebodin
15 views
-
2:26
Facebook SSOby Prashanth Adhikari
31 views
-
1:51
Facebook ssoby Prashanth Adhikari
18 views
-
1:43
mac wall attackby ManitobaRyan
66 views
-
2:47
Farmers Fight Back on Facebook - HubSpot TV (Ep. 100)by HubSpot TV
17 views
-
1:18
CT Video Series Facebook Privacy Helpby Bill Risser
43 views
-
0:29
SSO: I don't know what's going on in this video.by Hayden Eveningwood
8 views
-
0:21
Hacker SSO by Armageddon 2012-08-22 19-17-02-613.aviby uray syawaludin
16 views
All Comments (6)
Zhou Li 2 years ago
The fact is that ESPN's web site gets user's consent but the malicious web site doesn't. The malicious web site exploits a Facebook vulnerability to steal the access token possessed by ESPN and then impersonate ESPN to fetch DOB, email, and post on wall.
Sign in to YouTube
Sign in to YouTube
Greg Hamm 2 years ago
Thank you for bringing this to the ATTENTION of FaceBook...First!! And thanks for the job you have done - a great public service to the people that aren't aware of the PRIVACY SETTINGS!
Sign in to YouTube
Sign in to YouTube
vineet369 2 years ago
First was common sense, since name is already pubic.
Third one, is obvious, since at Request for Permission by FB, it specifically says, "Posts on my wall", which it can and most probably will do.
But how did YOU fetched DOB and email address, since those can only be accessed by ESPN, after we have allowed them to do so? From cookies or something?
Sign in to YouTube
Sign in to YouTube
alexariciu 2 years ago
nice work guys.
Sign in to YouTube
Sign in to YouTube