Уровень 0 · материалов: 2
В кластер включаются документы о конкретных технических уязвимостях в процессах аутентификации и авторизации, но не общие жалобы на удобство или поддержку процессов восстановления аккаунтов.
Общие признаки: обход двухфакторной аутентификации, ошибки в механизмах авторизации, компрометация учетных записей
Группа выше: Уязвимости систем аутентификации
Смысл: The main idea is that Yandex's 2FA implementation was flawed because it used a visible QR code (track_id) as the sole identifier for session authorization, allowing an attacker to hijack the session by intercepting that ID and polling the server faster than the legitimate user.
A security researcher demonstrates how Yandex's 2FA can be bypassed by scanning a user's QR code and stealing the session cookie via a race condition.
Смысл: The main idea is that a flaw in how Google handled Application-Specific Passwords allowed attackers to bypass 2FA and take full control of accounts, highlighting the danger of granting broad privileges to simplified authentication tokens.
Researchers found a way to bypass Google's 2FA using Application-Specific Passwords to access account settings and hijack accounts, a vulnerability Google has since patched.