via The Hacker News
10 giu 2020
Any Indian DigiLocker Account Could've Been Accessed Without Password
The Indian Government said it has addressed a critical vulnerability in its secure document wallet service Digilocker that could have potentially allowed a remote attacker to bypass mobile one-time passwords (OTP) and sign in as other users to access their sensitive documents stored on the platform. "The OTP function lacks authorization which makes it possible to perform OTP validation with
via The Hacker News
via The Hacker News
Iscriviti a:
Commenti sul post (Atom)
Nessun commento:
Posta un commento