ConsentFix Exposed
Key Takeaways
Examines an OAuth attack chain and what defenders can learn from legitimate services being abused
Full Transcript
In March, the XSS post kind of caught my eye cuz they say consent fix V3, the ultimate Azure attack chain, OAuth 2 abuse, two-factor authentication bypass, token exfiltration automated with Pipe Dream zero cost. So, I thought, "Oh, I want to go take a look at that." And I grabbed the URL. They have over a billion events, new data that they're collecting, over 5 million info stealer malware logs, chat messages from Telegram. Like, this is literally a Bible on how this could be put together. And I think this is fascinating for two reasons. One, because, okay, we have, sure, a cybercriminal sharing with their friends, telling everybody, "Hey, here's how to do this thing easy peasy for free." And it's also really wild because, okay, from a defender's point of view, now we're seeing exactly the kinds of services that they're using and abusing, which could very well be legitimate, hey, general-purpose, actual well-intended services, but that's the living off trusted sites technique, right?
Original Description
I take a look at a post advertising an OAuth attack chain, why attackers are openly sharing these techniques, and what defenders can learn from the legitimate services being abused.
Watch the full video here: https://youtu.be/T3oVdPCMDJw?si=1-h_BCuZprPcjdwk
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Related Reads
📰
📰
📰
📰
Complete Guide: Transferring Firestore Data Between Databases (Including Subcollections)
Dev.to · K-kibet
How I Built a CLI That Generates 12 Project Templates in 30 Seconds
Dev.to · ke jia
Debouncing vs Throttling Explained: Why Modern Web Applications Can’t Live Without Them
Medium · Programming
The Complete Roadmap to Become a Backend Developer in 2025
Dev.to · qing
🎓
Tutor Explanation
DeepCamp AI