Security firms demonstrate subdomain hijack exploit vs. EA/Origin

26 Jun
2019
26 Jun
'19
11:50 p.m.
'Israeli security firms Check Point and CyberInt partnered up this week to find, exploit, and demonstrate a nasty security flaw that allows attackers to hijack player accounts in EA/Origin's online games. The exploit chains together several classic types of attacks—phishing, session hijacking, and cross-site scripting—but the key flaw that makes the entire attack work is poorly maintained DNS.' -- source: https://arstechnica.com/information-technology/2019/06/security-firms-demons... Cheers, Peter -- Peter Reutemann Dept. of Computer Science University of Waikato, NZ +64 (7) 858-5174 http://www.cms.waikato.ac.nz/~fracpete/ http://www.data-mining.co.nz/
2133
Age (days ago)
2133
Last active (days ago)
0 comments
1 participants
participants (1)
-
Peter Reutemann