Quantcast
Channel: /dev/posts/
Viewing all articles
Browse latest Browse all 104

Malicious authorization server attack in UMA 2.0

$
0
0

In a previous post, I described a pass-the-permission-ticket vulnerability in UMA 2.0 in which a malicious UMA resource server could kindly ask a UMA client to give it access tokens actually intended for another UMA resource server. In this post, I am describing a similar attack when the authorization server is malicious.


Viewing all articles
Browse latest Browse all 104

Trending Articles