TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Researchers took over Booking.com accounts using a legitimate Facebook link

4 pointsby aviCCabout 2 years ago
The vulnerability exists in OAuth (social sign-in), used by almost every website today. If you are unfamiliar with OAuth, the post (in the first comment) explains it step-by-step with detailed diagrams.

1 comment

aviCCabout 2 years ago
<a href="https:&#x2F;&#x2F;salt.security&#x2F;blog&#x2F;traveling-with-oauth-account-takeover-on-booking-com" rel="nofollow">https:&#x2F;&#x2F;salt.security&#x2F;blog&#x2F;traveling-with-oauth-account-take...</a><p>Video: <a href="https:&#x2F;&#x2F;youtu.be&#x2F;IK_AV1UFS-0" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;IK_AV1UFS-0</a>