ãã¾ã¾ã§ Mix-up Attack 㯠Client ã AS æ¯ã« redirect_uri ã使ãåãã¦ããã°é²ããã¨ä¿¡ãããã¦ãã¾ããããããããé²ããªãã±ã¼ã¹ããããã£ã¦ã®ã OAuth ML ã«æ稿ããã¾ããã ç´°ãã解説ã¯è±èªèªãã§ãããã¨ãã¦ãã·ã¼ã±ã³ã¹ã«ããã¨ãããããã¨ã§ãã Attacker AS ã (Display Name ããã´çãéãã¦) ä¸è¦ Honest Client ã«è¦ãããã㪠Client (Attacker Client) ã Honest AS ã«ç»é²ãã¦ããå¿
è¦ãããã¾ãã User ã Attacker AS é¸ãã§ãã®ã« Honest AS ã«é£ã㧠Approve ãã¦ãã¾ã£ã¦ãé¨åããAttacker Proxy ãå©ç¨å¯è½ãªç¶æ³ (e.g., Client ã HTTP ãªã¨ã³ããã¤ã³ã㧠Honest AS ã®ãã°ã¤ã³ãã¿ã³çã
{{#tags}}- {{label}}
{{/tags}}