Jet Admin 允许攻击者创建一个恶意应用,并将其连接到目标用户的自定义域名。攻击者可以篡改认证配置,将流量重定向至由其控制的恶意应用。一旦该恶意应用与目标域名成功关联,若目标用户使用了 OAuth 提供商,则攻击者的工作区将自动获取受害者的 OAuth 客户端 ID 和客户端密钥。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet