mastodon.bida.im is part of the decentralized social network powered by Mastodon.
Un'istanza mastodon antifascista. autogestita, italofona con base a Bologna. Rispettosa di privacy e anonimato.

Server stats:

863
active users

Learn more

#ghosttoken

0 posts0 participants0 posts today

GhostToken: tutti gli account Google possono essere compromessi con un nuovo bug 0-day

Una società di sicurezza israeliana, ha scoperto una di nella piattaforma cloud di (GCP) soprannominata il 19 giugno 2022, che ha un impatto su tutti gli utenti di .

La “GhostToken” potrebbe consentire agli attori delle di rendere un’ dannosa “ e ”, rendendo l’ della vittima permanentemente infettato da un’app trojan.

redhotcyber.com/post/ghosttoke

The research team in Astrix uncovered #GhostToken - a 0-day #vulnerability in Google Cloud Platform (#GCP) allowing malicious #OAuth apps to become unremovable for Google users who installed them.

We had disclosed the vulnerability to Google who recently rolled out a patch for all users.
I've written a technical blog where you can read how we found the vulnerability and exploited it:
astrix.security/ghosttoken-exp

For those who are tight on time, the issue resides in the fact that any Google OAuth application is forcibly tied to a single GCP project. This supposedly makes easier to use any of GCP's services to develop OAuth apps.
However, we discovered that when the project associated with an OAuth app is deleted, the app enters a "limbo" state, being hidden from the user's management page (and thus unremovable), while its OAuth tokens are not revoked.

This primitive can be turned into an attack flow (as described in the blog), where an attacker controlling a malicious app can access the user's data without the user being able to revoke the access.

Astrix SecurityGhostToken - Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts - Astrix SecurityGhostToken - Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts