OpenSea has reportedly patched a vulnerability on its website which was capable of revealing the identity of its users.
The exploit is understood to have taken advantage of a cross-site search vulnerability. Imperva claimed OpenSea had misconfigured a library that resizes webpage elements that load HTML content from elsewhere which are typically used to place ads, interactive content, or embedded videos.
As OpenSea didn’t restrict this library’s communications, exploiters could use the information it broadcasts as an “oracle” to narrow down when searches return no results as the webpage would be smaller.through email or SMS which if clicked “reveals valuable information, such as the target’s IP address, user agent, device details, and software versions.
Imperva said OpenSea “quickly addressed the issue” and properly restricted the library’s communications and reported the platform “was no longer at risk of such attacks.”
Singapore Latest News, Singapore Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
What is ethical hacking, and how does it work?Learn about ethical hacking and its role in improving cybersecurity. Discover how ethical hacking works and its importance in vulnerability assessment and information security.
Read more »
One answer to productivity woes? Mental performance coaches.As companies struggle with productivity and fraying cultures, a Florida cybersecurity firm has a solution: targeting employee mind-set with mental performance coaches.
Read more »
Users getting hooked on ‘gas station heroin’ pills that have ‘painful opioid-like’ withdrawals: reportSupplements dubbed “gas station heroin” that give “opioid-like highs” are leading to addiction and overdoses, experts say.
Read more »
Meta considers a new social network, as decentralized model gains steamThe parent of Facebook adds to growing momentum for platforms that let users control moderation policies.
Read more »
Final Fantasy XIV Releases New Patch Alongside New Puma PartnershipSquareEnix and Puma have teamed up for an all-new apparel partnership tied to FinalFantasyXIV, as the game gets Patch 6.35. FinalFantasy
Read more »
A denim fix that's better than a patchThere’s a particular sick stomach lurch that happens when you rip a favorite pair of jeans, not unlike the feeling of losing a beloved pet or fumbling a fragile family heirloom. For many of us, the denim we live in becomes an inextricable part of our lives.
Read more »