繼OpenSSL漏洞後,開源安全軟件再曝安全漏洞。
攻擊者創建壹個使用真實站點地址的彈出式登錄窗口——
黑客可利用該漏洞給釣魚網站“變裝”,
騰訊,阿裏巴巴,QQ、新浪微博、淘寶網,支付寶,網易,
鑒於OAuth和OpenID被廣泛用於各大公司——如微軟、
OAuth 是壹個被廣泛應用的開放登六協議,
相關資料,
http://tetraph.com/covert_
http://techxplore.com/news/
http://phys.org/news/2014-05-
http://news.yahoo.com/
http://thehackernews.com/2014/
http://blog.kaspersky.com/
https://hackertopic.wordpress.com/2014/05/26/covert-redirect-attacks
http://www.foxnews.com/tech/
http://network.pconline.com.
http://computerobsess.blogspot.com/2015/05/covert-redirect.html
http://ittechnology.lofter.com/post/1cfbf60d_6f09f58
http://diebiyi.com/articles/security/covert-redirect/oauth-2-0-openid-covert-redirect/
https://zh.wikipedia.org/wiki/covert-redirect
http://media.sohu.com/
http://it.people.com.cn/n/
http://www.inzeed.com/kaleidoscope/covert-redirect/oauth-2-0-and-openid-covert-redirect/
http://www.baike.com/wiki/covert-redirect-bug
http://www.csdn.net/article/


