If you haven't seen the Microsoft OAuth vulnerability yet, you need to check it out. #nOAuth
Anyone in the world is able to access your apps AS YOU with MS OAuth if the app is configured to use email as the account identifier.
Next tweet contains a video demo:
In the disclosure blog below, @omercnet goes into the details of:
✔ How nOAuth works
✔ How we helped fix many vulnerable apps (including fellow authentication providers)
✔ How you can check if your app is vulnerable to nOAuth
descope.com/blog/post/noauth
123... and just like that, we are public beta - lnkd.in/gXbS-uuW! Amazing teamwork across the board. We would love to hear feedback from every builder out there. Call out to all the startup founders/engineers/product managers - please try the produ…lnkd.in/g22Fn5gm
Another sprint ends
Though Friday brings big relief
New bugs lie ahead
To any #developers reading this haiku - congrats on making it through the week! Hope you’re ready to do it all over again in a few days.
pic credit: @omercnet#descopers
kill -9 pa$$w0rds
Sorry, we thought this was a terminal instead of a Twitter feed.
Anyway, hello from Descope! We’re building something in the authentication space for developers and can’t wait to share it with you.
Visit our site if you’re curious: descope.com/
ALT Hi, we're Descope! This is an animated GIF of our company logo.
All @SecurityBSides organizers around the world - make sure to check out the message from BSides Global on the organizer mailing list in preparation for our next phase of growth.
Please RT for visibility...
Thanks!
Infosec peeps, Mitiga is growing in the US and we’re hunting for hunters! would appreciate reshares and referrals, and promise a bottle/meal of your choosing to return the favor ;) linkedin.com/posts/omercohen…
יש לכם דיסקטים ישנים בגודל 5.25 אינץ׳? אשמח לאמץ אותם!
שוכב לכם בבית מחשב עתיק עם כונן לדיסקטים כאלו? עוד יתר טוב!
אשמח ל-retweet כדי להפיץ את הבשורה. כבר די קשה למצוא את הדברים האלו והרבה פעמים אנשים פשוט זורקים אותם לרחוב...
[#BHUSA] Need plans for Tuesday night? Register for our party, Gin & Jazz, at 1923 Bourbon Bar. Meet up with your peers and celebrate an incredible week at @BlackHatEvents. Register now: bit.ly/2MNk1dp#SOAR#DFIR
Stoked to announce @viewfromabook will be attending @BsidesTLV on June 24th. 🙌
We will have more details on where to meet us soon, but drop a note if you'll be attending as well. We're looking forward to seeing our friends!
Our annual @BsidesTLV CTF is almost upon us!
Expect many interesting new challenges to keep you occupied for the coming weeks
Have fun, and we will see you all at #BSidesTLV2019bsidestlv.com/ctf
*schedule and release dates may still change*
We have decided to cancel most training workshops and refund all the tickets purchased so far. Ethical Hacking 101 workshop and the UEFI & CHIPSEC Development for Security Researchers will both be available at 200ILS (~$55) buff.ly/2wz6Inu