logo

BlackHat presentation demo vids: SugarSync

ID: 1e27ed34-326c-54fb-ac3f-8b7a9cfcaa09

STIX ID: report--1e27ed34-326c-54fb-ac3f-8b7a9cfcaa09

Feed Name: SensePost Blog

Threat Score
65/100

Date Published: 2009-08-06

Date Updated: 2026-04-29

...
...

This write-up from a BlackHat 2009 presentation demonstrates that SugarSync's password reset process exposed short, guessable reset tokens and allowed unlimited, long-lived reset links; combined with username enumeration and cloud-scale requests, an attacker could mass-generate valid tokens and brute-force account resets over time.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.