Settings

Theme

Account Takeover Attack on X via OAuth Impersonation

twitter.com

2 points by grinich 5 months ago · 1 comment

Reader

sherdil2022 5 months ago

This is scary.

The url says www.calender.google.com - typo - calender instead of calendar - but still google.com.

If the TLD is legit, how can anyone figure out this is a suspicious app?

Even a legitimate app asking for full-access to an account shouldn’t be approved by X.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection