[POC] Google OAuth "MultiLogin" endpoint 0-day
by Farfallaiero - Friday December 29, 2023 at 05:40 PM
#91
interesting thread..let me check ..thanx for sharing mate!!
Reply
#92
Amazing discovery, thanks for sharing this!
Reply
#93
(12-29-2023, 05:40 PM)Farfallaiero Wrote: Informational POC


Multiple information-stealing malware families are abusing an undocumented Google OAuth endpoint named "MultiLogin" to restore expired authentication cookies and log into users' accounts, even if an account's password was reset.
Rhadamanthys, Risepro, Meduza and Stealc Stealer adopted this technique. On December 26, White Snake also implemented the exploit.

Thabkyou for this
Reply
#94
lets see this...
Reply
#95
very interresting. Thanks
Reply
#96
thanks for the share my guy
Reply
#97
Cool post sigma!
Reply
#98
this is what i was looking for. hope this still works
Reply
#99
okay okay is this even working still?
Reply
Free 0d sounds like something unrealistic
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 66 2,543 07-21-2026, 11:59 AM
Last Post: Yunu599
  new wordpress website takeover vuln (video + poc ) zinzeur 312 27,323 03-28-2026, 02:43 AM
Last Post: toshi99
  Cool Remote Patching ETW/Amsi PoC pepeloco 6 2,098 02-08-2026, 07:58 AM
Last Post: zeroday99
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 79 02-07-2026, 03:32 PM
Last Post: cysc
  POC CVE-2025-24071 caca28sapo1 15 810 02-07-2026, 08:53 AM
Last Post: hacker0123



 Users browsing this thread: 2 Guest(s)