I will burn your servers to the ground, foul villain
Enekk @ Enekk @lemmy.world Posts 0Comments 28Joined 2 yr. ago
Enekk @ Enekk @lemmy.world
Posts
0
Comments
28
Joined
2 yr. ago
Deleted
Permanently Deleted
The attack vector is as follows:
The various physical dongles prevent this by using the asking domain as part of the hash. If you activated the dongle on Evil.com, it'll do nothing on Good.com (except hopefully alerting the SOC at Good.com about a compromised username and password pair).