Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Account pre-hijacking

From Wikipedia, the free encyclopedia
Class of security exploit

Account pre-hijacking attacks are a class ofsecurity exploit related toonline services. They involve anticipating a user signing up for an online service and signing up to the service in their name, and then taking over their account when they attempt to register it themselves.[1][2][3] The attack relies on confusion between accounts created byfederated identity services and accounts created using e-mail addresses and passwords, and the failure of services to resolve this confusion correctly.[1]

Pre-hijacking was first identified as a class of vulnerabilities in 2022, based on research funded byMicrosoft's Security Response Center.[4][5]

Out of 75 online services surveyed, 35 were found to be vulnerable to various forms of the exploit. Vulnerable services includedDropbox,Instagram,LinkedIn,WordPress andZoom. The existence of the vulnerability was reported to all the service providers before publication of the paper.[5]

See also

[edit]

References

[edit]
  1. ^abKovacs, Eduard (May 24, 2022)."Hackers Can 'Pre-Hijack' Online Accounts Before They Are Created by Users".Security Week. Retrieved2022-05-31.
  2. ^Brinkmann, Martin (2022-05-24)."Pre-hijacking Attacks of user accounts are on the rise".gHacks Technology News. Retrieved2022-05-31.
  3. ^Andrew Paverd (May 23, 2022)."New Research Paper: Pre-hijacking Attacks on Web User Accounts".Microsoft Security Response Center. Retrieved2022-05-31.
  4. ^Dickson, Ben (2022-05-30)."Dozens of high-traffic websites vulnerable to 'account pre-hijacking', study finds".The Daily Swig. Retrieved2022-05-31.
  5. ^abSudhodanan, Avinash; Paverd, Andrew (2022-05-20). "Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web".arXiv:2205.10174 [cs.CR].
Hacking in the 2020s
← 2010s
2030s →
Major incidents
2020
2021
2022
2023
2024
2025
2026
Groups
Individuals
Majorvulnerabilities
publiclydisclosed
Malware
2020
2021
2022
2023
2024
2025


Stub icon

Thiscomputer security article is astub. You can help Wikipedia byadding missing information.

Retrieved from "https://en.wikipedia.org/w/index.php?title=Account_pre-hijacking&oldid=1252852703"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp