Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

Caution: Keep out of reach of children.


interests / rocksolid.shared.news / Gab oauth2 hack

SubjectAuthor
o Gab oauth2 hackAnonymous

1
Gab oauth2 hack

<0c013b042edb29c29c5716072cf8a5c4$1@www.novabbs.com>

  copy mid

https://novabbs.com/interests/article-flat.php?id=250&group=rocksolid.shared.news#250

  copy link   Newsgroups: rocksolid.shared.news
Path: i2pn2.org!.POSTED!not-for-mail
From: Anonym...@novabbs.i2p (Anonymous)
Newsgroups: rocksolid.shared.news
Subject: Gab oauth2 hack
Date: Fri, 12 Mar 2021 02:16:37 +0000
Organization: novaBBS
Message-ID: <0c013b042edb29c29c5716072cf8a5c4$1@www.novabbs.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Info: i2pn2.org; posting-account="retrobbs1";
logging-data="2202"; mail-complaints-to="usenet@i2pn2.org"
User-Agent: Rocksolid Light (news.novabbs.com/getrslight)
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on novabbs
X-Rslight-Site: $2y$10$TV5Gw2jeG8Wjvnvzbv.E2us05SGs4gCMRex3cNwkQBdjThZbKZwB2
 by: Anonymous - Fri, 12 Mar 2021 02:16 UTC

I've messed briefly with oauth2 in the past but the idea always seemed a bit risky, especially since the project I was working on some code for didn't really need it. I guess they just thought is was cool.

oauth2 works by "delegating user authentication to the service that hosts the user account, and authorizing third-party applications to access the user account"

From https://noqreport.com/2021/03/08/gab-ceo-andrew-torba-responds-to-hack-it-was-not-a-new-attack/

Social network Gab was down today following what they believed was a new attack. It was revealed that this was a continuation of an old attack that took place last week as OAuth2 tokens were reused to get into several accounts. The site was immediately shut down but is now back online.

CEO Andrew Torba posted an update explaining what happened and why there is no need for users to reset their passwords.

The attacker who stole data from Gab harvested OAuth2 bearer tokens during their initial attack. Though their ability to harvest new tokens was patched, we did not clear all tokens related to the original attack. By reusing these old tokens, the attacker was able to post 177 statuses in an 8-minute period today. We have not independently verified the information that the hacker posted is authentic.

Gab immediately took the site offline, suspecting this was a new attack. We have been able to confirm it was not a new attack, have cleared all compromised tokens, and are requiring users to log in again. As this is not a new attack and no new data has been compromised, there is no need to change your password or take any other action.

We apologize for the inconvenience, and are very confident this will not happen again.
--
Posted on novaBBS
www.novabbs.com

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor