The Rise of Consent and Other Application-based Phishing Attacks
OAuth consent-based and other application phishing attacks: anatomy, variants, detection, and prevention.
OAuth consent-based and other application phishing attacks: anatomy, variants, detection, and prevention.
How the HANA client Secure User Store protects credentials, what can go wrong, and best practices.
HANA series part 3: federated authentication — SAML, logon tickets, JWTs, Kerberos, and session cookies.
HANA series part 2: password-based authentication mechanisms and protecting protocol traffic with TLS.
HANA series part 1: protocol basics, traffic dissection, packet crafting, tenant discovery, and authentication 101.
Why browser fingerprinting — and the browser vendors' war against it — challenges identity security.
Old notes and new findings on SAP archive files, path traversals, and in-archive signature pitfalls.
How mobile malware steals 2FA codes and bypasses MFA — an identity-lens view with a Cerberus case study.