Twitter account hijack @Costalfy

Disclosed: 2023-09-27 22:15:01 By checkmateemperor To liberapay
Low
Vulnerability Details
##Summary: Broken Link Hijacking (BLH) is a web-based attack where it exploits external links that are no longer valid. The attackers take over this expired, stale, and invalid external links on credible websites or web applications for malicious or fraudulent purposes. Link Hijacking attacks occur because the website/ web application continues to contain links to expired/ stale resources/pages (loaded using external URLs). So i found a twitter account of one of the members of **liberapay** which is **Andy Costanza** is broken, anyone can claim that account and can scam with it . {F2642478} ##Steps To Reproduce: 1- Go to ``` https://liberapay.com/Andy_Costanza/ ``` and Click on the twitter button . {F2642439} 2-now it redirect you to Attacker ( My ) Profile . {F2642468} > - Those interested to get more infomation about **Andy Costanza** at https://liberapay.com/Andy_Costanza/ should be cautious of potential phishing or scam attempts. It is advised to take prompt action to ensure safety and security. ## Impact Since the links can be hijacked so any attacker can claim the link and make fake Twitter profile of **Andy Costanza** and can do scam with them.
Actions
View on HackerOne
Report Stats
  • Report ID: 2125346
  • State: Closed
  • Substate: resolved
  • Upvotes: 12
Share this report