[POC] Google OAuth "MultiLogin" endpoint 0-day
by Farfallaiero - Friday December 29, 2023 at 05:40 PM
#41
(Dec 29, 2023, 05:40 PM)Farfallaiero Wrote: Informational POC


Multiple information-stealing malware families are abusing an undocumented Google OAuth endpoint named "MultiLogin" to restore expired authentication cookies and log into users' accounts, even if an account's password was reset.
Rhadamanthys, Risepro, Meduza and Stealc Stealer adopted this technique. On December 26, White Snake also implemented the exploit.

thank you so very much sir!
Reply
#42
You are my lord
Reply
#43
Nice discovery, that looks OP
Reply
#44
thank you for the share
Reply
#45
been patched long ago
Reply
#46
let me seeeeeeddd

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#47
would help in my security findings
Reply
#48
No way this is still a 0day if you providing the information for free
Reply
#49
thank you for sharing
Reply
#50
Thanks for your sharing

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Attempted Scamming | Public Data | https://breachforums.rs/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Ban Any Discord Exploit phineasfisherman 7 432 1 hour ago
Last Post: sniperx86
  Dokan Pro Unauthenticated SQL Injection POC | CVSS 10 Loki 42 3,725 3 hours ago
Last Post: d39ug
  {SECRET} DATABASE OF EXPLOITS lulagain 435 26,439 Yesterday, 06:11 AM
Last Post: DirtyEra
  New Zer0 Day Wordpress A3g00n 81 3,363 Yesterday, 03:06 AM
Last Post: DirtyEra
  Wordpress Elementor 3.11.6 Exploit - Full Takeover TheGoodlife 102 19,722 May 04, 2026, 06:45 AM
Last Post: eztocard

Forum Jump:


 Users browsing this forum: 1 Guest(s)