Security and Privacy of Social Logins (II): PostMessage Security in Single Sign-On |
|
|
|
Bad regex used in Facebook Javascript SDK leads to account takeovers in websites that included it |
|
|
|
[Google VRP] Hijacking Google Docs Screenshots |
|
|
|
Facebook DOM Based XSS using postMessage |
|
|
|
Hunting postMessage Vulnerabilities |
|
|
|
Account takeover via postMessage |
|
|
|
Exploiting post message to steal and replace user’s cookies |
|
|
|
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token |
|
|
|