• AD
LIFETIME Warranty on All Electronic Products
V2 Cigs - electronic cigarettes - #1 Ecig Brand in the World!
Enter Coupon Code techcw for a 10% Discount Anytime

OpenID Security Flaw Lets Hackers Impersonate Users

Post a reply

Smilies
:D :) ;) :( :o :shock: :? 8-) :lol: :x :P :oops: :cry: :evil: :twisted: :roll: :!: :?: :idea: :arrow: :| :mrgreen: :geek: :ugeek:
View more smilies
BBCode is ON
[img] is ON
[flash] is OFF
[url] is ON
Smilies are ON
Topic review
   

Expand view Topic review: OpenID Security Flaw Lets Hackers Impersonate Users

OpenID Security Flaw Lets Hackers Impersonate Users

Post by TechCW » Tue May 10, 2011 3:32 am

Researchers have detected a serious vulnerability in some implementations of OpenID 2.0, which could enable malicious attackers to could gain unauthorized access to a user's account by altering traveling information.

The security flaw, which exists in several instances of the parties that implement Attribute Exchange (AX), a function that permits sites to exchange information between endpoints, prevents some sites from confirming that the information passing through AX has been signed.

Subsequently, AX could validate all of the passing information, including the identity of an unknown user, which enables an attacker to modify the data to his or her advantage or impersonate a victim without detection.

:arrow: Full Story: CRN

Top

Links | XML Sitemap
cron