Impersonating users by abusing broken “Sign in with” implementations

Several applications implementing “Sign in with GitHub” have been found to be using a mutable identifier (username) to match external users to the internal user management system. This allows attackers to completely take over accounts whose GitHub username has changed.

Aeneas Rekkas headsot
Aeneas Rekkas

Founder & CTO

Nov 27, 2018