Hi Saurabh,

The idea is simple

if you want to login to website (x) using your google account you will do this:

1) login to your account in (x) website

2) link your google account

3) now when u click on login with google you will log into your account

the attack is instead of linking my account (me the attacker) into your account (you are the victim)

so when u click the evil link my google account will be linked into your account

so i will open (x) website and press login with google

and i will enter my google account (which i linked into your account)

then i will gain access to your account :)

I hope this makes it more clear

Sign up to discover human stories that deepen your understanding of the world.

Free

Distraction-free reading. No ads.

Organize your knowledge with lists and highlights.

Tell your story. Find your audience.

Membership

Read member-only stories

Support writers you read most

Earn money for your writing

Listen to audio narrations

Read offline with the Medium app

Yasser Mohammed (@n3r0li)
Yasser Mohammed (@n3r0li)

Written by Yasser Mohammed (@n3r0li)

My Name Is Yasser and I am a CTF player and Competitive programmer, I Love to build things then break into it.

Responses (1)

Write a response