[OAUTH-WG] OAuth2 attack surface....

William Mills <wmills_92105@yahoo.com> Mon, 25 February 2013 22:22 UTC

Return-Path: <wmills_92105@yahoo.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9747C21E80FA for <oauth@ietfa.amsl.com>; Mon, 25 Feb 2013 14:22:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.054
X-Spam-Level:
X-Spam-Status: No, score=-1.054 tagged_above=-999 required=5 tests=[AWL=-1.056, BAYES_50=0.001, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 60quMqtvx8Pn for <oauth@ietfa.amsl.com>; Mon, 25 Feb 2013 14:22:42 -0800 (PST)
Received: from nm19.bullet.mail.ne1.yahoo.com (nm19.bullet.mail.ne1.yahoo.com [98.138.90.82]) by ietfa.amsl.com (Postfix) with ESMTP id 65F1521E80F6 for <oauth@ietf.org>; Mon, 25 Feb 2013 14:22:29 -0800 (PST)
Received: from [98.138.226.180] by nm19.bullet.mail.ne1.yahoo.com with NNFMP; 25 Feb 2013 22:22:25 -0000
Received: from [98.138.87.8] by tm15.bullet.mail.ne1.yahoo.com with NNFMP; 25 Feb 2013 22:22:25 -0000
Received: from [127.0.0.1] by omp1008.mail.ne1.yahoo.com with NNFMP; 25 Feb 2013 22:22:25 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 190259.53793.bm@omp1008.mail.ne1.yahoo.com
Received: (qmail 23725 invoked by uid 60001); 25 Feb 2013 22:22:24 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1361830944; bh=QO7T0D/i8NQRKUFueX46qmtTNtDae6rJfaC5v+ho65I=; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Reply-To:Subject:To:MIME-Version:Content-Type; b=r6S0aV76pw2acfTqNyEjD2PeD43+Kw6oZVy4vXev9H+fsXBIztue2SUqSr0MPqnH3w3bVIPuTG2Q8SEITuatP/cBnABDWiIvx0wWi7YRNM5VMHFh3o5LpGq9Z2QYUEIEGcl35yzPGU5iWL8hy6LeKzDS+mgj9S65B4Y+bB9mQUQ=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Reply-To:Subject:To:MIME-Version:Content-Type; b=fenGg/5K8eRTidbdQTJjihaz2J2vwyQY7Mge+pHBSERoxjiui0s29Vc3sbOl/gbAFCC1TV/2fdSNjXBFmCjxs9EHJmF4IDh3wSaBBdnQ5BNLD5nelTCoa+AUZ1BM2nS+n7bKl4eY/HMSitSslgr2e6j23jH82Onuh083MJY7+cU=;
X-YMail-OSG: EqjgQGkVM1nHCxWQek5tJHJKKgr9AwxBnf_ygSnsQ0toxg2 Tvow0QnP.2EVuYA.yB1wzxPn229vCZce_YiCqjG8pxJ55G19A2EeAfz6yjJv Gn6Bkws.tylEvO908Kc4bMX76YbqeBYD2fIkKstiRHJkgZthDtJX3LaccCSu FjjsiFAY0Kv7aPjhHg.kJtZgJwhgkdWEULy1jvWmgo4iBZ2XqEt1Eu7vIfYK t3rRNWtv7jBSPJlomBJ7lDkELz.NHhXORQEsz5O.wi2RBgtfYE._Lpe7_arZ EBxEy01E7eOVVYUtCeYYuAGFc151.gJEmyTMBRvl09eZu7C0l5pM47fJUxEe qk9WCdfBaa_jbLtq8lGsHPaa.m63l6YVheCrg8k2TC2cwVNqWEdhY9jrTHu5 cG9KniIL4TKv7z1oYQElJhl2Au1pa5X1a06HxxdZm8LCYbdWmCp575goStKv 5ETvgKC7SRIcRpuXnIsSLOlFjbEjgH2DvCeXTEeD7UiKzhEWw6cjawb94k_U w5slz56I2DFHfdZ82ky9pCW0-
Received: from [209.131.62.113] by web31812.mail.mud.yahoo.com via HTTP; Mon, 25 Feb 2013 14:22:24 PST
X-Rocket-MIMEInfo: 001.001, SSB0aGluayB0aGlzIGlzIHdvcnRoIGEgcmVhZCwgSSBkb24ndCBoYXZlIHRpbWUgdG8gZGl2ZSBpbnRvIHRoaXMgOigBMAEBAQE-
X-Mailer: YahooMailWebService/0.8.135.514
Message-ID: <1361830944.13340.YahooMailNeo@web31812.mail.mud.yahoo.com>
Date: Mon, 25 Feb 2013 14:22:24 -0800
From: William Mills <wmills_92105@yahoo.com>
To: O Auth WG <oauth@ietf.org>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="1458549034-398514229-1361830944=:13340"
Subject: [OAUTH-WG] OAuth2 attack surface....
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: William Mills <wmills_92105@yahoo.com>
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Feb 2013 22:22:42 -0000

I think this is worth a read, I don't have time to dive into this :(