Re: [OAUTH-WG] OAuth2 attack surface....

William Mills <wmills_92105@yahoo.com> Mon, 25 February 2013 22:42 UTC

Return-Path: <wmills_92105@yahoo.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F24121E80FE for <oauth@ietfa.amsl.com>; Mon, 25 Feb 2013 14:42:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.304
X-Spam-Level:
X-Spam-Status: No, score=-2.304 tagged_above=-999 required=5 tests=[AWL=0.294, BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d2IP-sc8l2lE for <oauth@ietfa.amsl.com>; Mon, 25 Feb 2013 14:42:15 -0800 (PST)
Received: from nm21-vm1.bullet.mail.ne1.yahoo.com (nm21-vm1.bullet.mail.ne1.yahoo.com [98.138.91.46]) by ietfa.amsl.com (Postfix) with ESMTP id E6EC821E8104 for <oauth@ietf.org>; Mon, 25 Feb 2013 14:42:14 -0800 (PST)
Received: from [98.138.226.180] by nm21.bullet.mail.ne1.yahoo.com with NNFMP; 25 Feb 2013 22:42:14 -0000
Received: from [98.138.88.237] by tm15.bullet.mail.ne1.yahoo.com with NNFMP; 25 Feb 2013 22:42:14 -0000
Received: from [127.0.0.1] by omp1037.mail.ne1.yahoo.com with NNFMP; 25 Feb 2013 22:42:14 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 365688.98898.bm@omp1037.mail.ne1.yahoo.com
Received: (qmail 3143 invoked by uid 60001); 25 Feb 2013 22:42:14 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1361832133; bh=QSxzc1ronDdTL5FkazdSoaxqpQ8BAqbiNmyjs9vshkM=; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:In-Reply-To:MIME-Version:Content-Type; b=hF9sb2A2qclUmKumGuCp3lgiquigVEyrbMjt8ITDFiCEaxJqDOT7QqT+OpV7PooxWglF+gP6rkdqK3BHXBHyMdpcVGRuLACUNA60GvzWMlmZOs+QAbkTqyyEFOhhYwUbHgm99ySNojxMMwPAwTLwGbyeT5giIq0SbUy7+d7kzL8=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:In-Reply-To:MIME-Version:Content-Type; b=nXH6NmEb3oEtbgZhrBKm2M7YnfNMw3sOaj9TIBUPoe1Zv5NOi01DbjbrJld/PaNgqsvfBf5wzZVoCYgD0Hgs2fMwa3cwTC7kbeOG2DaOoBGdv8H88ChJ21zcjigZ0dS633mSFAFczEWLUVHovap6FUw4/1bJiZAqYZQdeje0Pbg=;
X-YMail-OSG: FhrYC54VM1njfTm1DqhVqb.m5PLtUK86UZVb5TuwJy7zq58 dOOb9_jdf89EvjSt4RgvV10hhmbQ_L9KCmV1ApVMcz3DHQvKF_VsQPqEgGz8 HKt2cbsjoYu_W4fR4fvZVhUc46ae5aH.87zpD00D6T1ETUGZzAb7owTzoEfp j.SAIjBckiNpzqx8WOoQ8ohAL_uHeHs7gyjoyU4D1vMq90bWW8EY9AGWw56P RTcLdC5aEZZItuT1JZdoip2jBrCtmaQxWT9AS680pLu8FTAiJjyCJcRvZimD eqyCRs61gKJeI.9k04Sc8sI6zlmsRXdX_h8HcsYijeIqLSkHn0cDQLOSkW_B XujS9..YtX1MEO91u_6OhDU4BACLBSJA1SIdlXd3hhRPWr7l.RCb5zAlvub4 y29bcTF1y0M2eTMJm8MTuW8AAfYTR3ecqlKoFgtKHY_T921sfcIO_KKov6PD lCVKw72fxqOiaV7mV0ppRVp.Z3lnSk8QQj1KijW89Z9zlUthct8hpT5_RFkQ Vvy0wSUQqoDHJxquLqpzsTieWLeTIT_VPb662qRZT8wL_YifYAhsIXJ5zb1A 3RJygv55JJQ4LmTI9czWG0P.FnlszcSSRdNI76ZC338.ZffWjFBFtRJirogy Wv20w.Lz8KgEovDwJ7JffawKUjTuXZwemIVmwhNDrt37KfBMDyxyFBHW6XRd BIJzMDFXXi8DgqnXQr43SZjFnhQHyvXuZnl_yxN_rpSHUmH2W.SY-
Received: from [209.131.62.145] by web31816.mail.mud.yahoo.com via HTTP; Mon, 25 Feb 2013 14:42:13 PST
X-Rocket-MIMEInfo: 001.001, CgoKCkRPSCEhISDCoGh0dHA6Ly9ob21ha292LmJsb2dzcG90LmNvLnVrLzIwMTMvMDIvaGFja2luZy1mYWNlYm9vay13aXRoLW9hdXRoMi1hbmQtY2hyb21lLmh0bWwKCgpfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXwogRnJvbTogUGhpbCBIdW50IDxwaGlsLmh1bnRAb3JhY2xlLmNvbT4KVG86IFdpbGxpYW0gTWlsbHMgPHdtaWxsc185MjEwNUB5YWhvby5jb20.IApTZW50OiBNb25kYXksIEZlYnJ1YXJ5IDI1LCAyMDEzIDI6MjggUE0KU3ViamVjdDogUmU6IFtPQVVUSC1XR10gT0F1dGgyIGF0dGEBMAEBAQE-
X-Mailer: YahooMailWebService/0.8.135.514
References: <1361830944.13340.YahooMailNeo@web31812.mail.mud.yahoo.com> <E4A6D91D-2BC8-4F2E-9B1C-D1362A0E3608@oracle.com> <1361831644.50183.YahooMailNeo@web31801.mail.mud.yahoo.com>
Message-ID: <1361832133.97884.YahooMailNeo@web31816.mail.mud.yahoo.com>
Date: Mon, 25 Feb 2013 14:42:13 -0800
From: William Mills <wmills_92105@yahoo.com>
To: Phil Hunt <phil.hunt@oracle.com>, O Auth WG <oauth@ietf.org>
In-Reply-To: <1361831644.50183.YahooMailNeo@web31801.mail.mud.yahoo.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="-1238014912-1521137038-1361832133=:97884"
Subject: Re: [OAUTH-WG] OAuth2 attack surface....
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: William Mills <wmills_92105@yahoo.com>
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Feb 2013 22:42:15 -0000




DOH!!!  http://homakov.blogspot.co.uk/2013/02/hacking-facebook-with-oauth2-and-chrome.html


________________________________
 From: Phil Hunt <phil.hunt@oracle.com>
To: William Mills <wmills_92105@yahoo.com> 
Sent: Monday, February 25, 2013 2:28 PM
Subject: Re: [OAUTH-WG] OAuth2 attack surface....
 

Whats the link?

Phil

Sent from my phone.

On 2013-02-25, at 14:22, William Mills <wmills_92105@yahoo.com> wrote:


I think this is worth a read, I don't have time to dive into this :(
_______________________________________________
>OAuth mailing list
>OAuth@ietf.org
>https://www.ietf.org/mailman/listinfo/oauth
>