BlackHat presentation demo vids: SugarSync
ID: 1e27ed34-326c-54fb-ac3f-8b7a9cfcaa09
STIX ID: report--1e27ed34-326c-54fb-ac3f-8b7a9cfcaa09
Feed Name: SensePost Blog
Threat Score
This write-up from a BlackHat 2009 presentation demonstrates that SugarSync's password reset process exposed short, guessable reset tokens and allowed unlimited, long-lived reset links; combined with username enumeration and cloud-scale requests, an attacker could mass-generate valid tokens and brute-force account resets over time.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
