Category:Attack Categorisation By Attacker Model: Access to Valid Token: Difference between revisions

From Single Sign-On Attacks
Jump to navigation Jump to search
No edit summary
No edit summary
Line 1: Line 1:
The attacker knows the component for identification and authentication of the user. The goal in this class of attacks is to expand the rights provided by the given token. Using of [https://en.wikipedia.org/wiki/Cross-site_scripting Cross-Site-Scripting (XSS)] attack the malefactor can obtain a token.
The attacker knows the component for identification and authentication of the user. The goal in this class of attacks is to expand the rights provided by the given token. Using of [https://en.wikipedia.org/wiki/Cross-site_scripting Cross-Site-Scripting (XSS)] attack the malefactor can obtain a token.


[[File:MA2.jpg]]
[[File:MA2.jpg|centre]]


==Part of main category:==
==Part of main category:==
*[[:Category:Attack_Categorisation_By_Attacker_Model]]
*[[:Category:Attack_Categorisation_By_Attacker_Model]]
[[Category:Attack_Categorisation_By_Attacker_Model]]
[[Category:Attack_Categorisation_By_Attacker_Model]]

Revision as of 21:08, 8 December 2015

The attacker knows the component for identification and authentication of the user. The goal in this class of attacks is to expand the rights provided by the given token. Using of Cross-Site-Scripting (XSS) attack the malefactor can obtain a token.

File:MA2.jpg

Part of main category:

Pages in category "Attack Categorisation By Attacker Model: Access to Valid Token"

The following 3 pages are in this category, out of 3 total.