Security firms demonstrate subdomain hijack exploit vs. EA/Origin

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12JFAF9HL89pSmk0ZRUUVRkm-v1QtG-S0D52QKr1hf-LdA@mail.gmail.com>
'Israeli security firms Check Point and CyberInt partnered up this
week to find, exploit, and demonstrate a nasty security flaw that
allows attackers to hijack player accounts in EA/Origin's online
games. The exploit chains together several classic types of
attacks—phishing, session hijacking, and cross-site scripting—but the
key flaw that makes the entire attack work is poorly maintained DNS.'

-- source: https://arstechnica.com/information-technology/2019/06/security-firms-demonstrate-subdomain-hijack-exploit-vs-eaorigin/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.