Problem with OAuth
Unknown
Vulnerability Details
There are many website that tracks the unfollowers and all like:
http://unfollowerstats.com
[Steps]:
1. Login with ur twitter account, i.e. [email protected]
2. Open http://unfollowerstats.com, This will ask you to login with twitter:
3. you will get a link like this:
https://api.twitter.com/oauth/authenticate?oauth_token=xpXP21WOzwvsocu7yjQBafl8BKRtKdeH
4.
Open Another browser and login with some other user i.e. : [email protected]
5.
Open this oAuth link(https://api.twitter.com/oauth/authenticate?oauth_token=xpXP21WOzwvsocu7yjQBafl8BKRtKdeH) on the other browser
6.
Authorize this OAuth with user [email protected]
7. Go to the first browser, and refresh the page and continue to authorize. You will be logged into http://unfollowerstats.com with [email protected] user
-- Tested with 2 such websites
Actions
View on HackerOneReport Stats
- Report ID: 46485
- State: Closed
- Substate: resolved
- Upvotes: 4