<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mobile on Sicksec</title><link>https://blog.sicks3c.io/tags/mobile/</link><description>Recent content in Mobile on Sicksec</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Sicksec</copyright><lastBuildDate>Fri, 01 Sep 2023 07:32:53 +0800</lastBuildDate><atom:link href="https://blog.sicks3c.io/tags/mobile/index.xml" rel="self" type="application/rss+xml"/><item><title>Account Takeover via an Unsanitized Facebook OAuth Redirect Scheme</title><link>https://blog.sicks3c.io/research/ato-via-facebook-oauth-due-unsanitized-schema-allows-to-steal-oauth-token/</link><pubDate>Fri, 01 Sep 2023 07:32:53 +0800</pubDate><guid>https://blog.sicks3c.io/research/ato-via-facebook-oauth-due-unsanitized-schema-allows-to-steal-oauth-token/</guid><description>&lt;h1 id="deep-dive-into-an-oauth-exploit-a-0-day-case-study">Deep Dive into an OAuth Exploit: A 0-Day Case Study&lt;a class="heading-anchor" href="#deep-dive-into-an-oauth-exploit-a-0-day-case-study" aria-label="Link to Deep Dive into an OAuth Exploit: A 0-Day Case Study">#&lt;/a>&lt;/h1>
&lt;p>&lt;strong>Hello Everyone,&lt;/strong>&lt;/p>
&lt;p>In our continuous hunt for novel attack vectors and security challenges, &lt;a href="https://x.com/wld_basha" target="_blank" rel="noreferrer">&lt;strong>mainteemoforfun&lt;/strong>&lt;/a> and I embarked on an in-depth exploration of &lt;strong>mobile authentication mechanisms&lt;/strong>. Our efforts culminated in the discovery of a striking &lt;strong>0-day vulnerability&lt;/strong> back in &lt;strong>2023&lt;/strong> that has since been patched.&lt;/p>
&lt;p>This vulnerability enabled us to potentially hijack user sessions on websites utilizing &lt;strong>Facebook’s “Login With Facebook”&lt;/strong> feature. By manipulating the &lt;strong>&lt;code>redirect_uri&lt;/code>&lt;/strong> parameter in the &lt;strong>OAuth&lt;/strong> flow, an attacker could redirect authentication tokens to a host under their control.&lt;/p></description></item></channel></rss>