FB pixel

Attackers spoofing OAuth client IDs to cloak Entra compromise attempts: Proofpoint

Categories Access Control  |  Biometrics News
Attackers spoofing OAuth client IDs to cloak Entra compromise attempts: Proofpoint
 

Proofpoint has identified multiple cloud campaigns in which attackers used forged OAuth client IDs to reveal Microsoft Entra ID accounts. The attackers can then test credentials like passwords without triggering compromised-credential alerts.

The technique allows threat actors to test large numbers of usernames and passwords without creating or registering an OAuth application. An OAuth client ID is a public identifier used to identify the application making an authentication request.

The cyberattack technique relies on differences in the types of authentication errors generated. Entra ID returns different AADSTS error codes depending on whether the username exists, whether the password is correct, and whether the supplied client ID corresponds to a registered application.

Threat actors can interpret these error codes to differentiate nonexistent accounts from valid users and identify valid username-password combinations. This works even if the authentication request fails because the application identifier is not recognized.

For example, a fabricated client ID can reveal that a username and password were accepted before Entra ID rejected the request because the supposed application does not exist. The company says this allows valid credentials to be identified without generating a successful sign-in record.

Users must implement effective monitoring

Proofpoint says users should not treat an “application-not-found” error as a configuration problem. The error can occur after Entra ID has accepted a valid username and password but rejected the request because the supplied client ID does not correspond to a registered application.

The event may indicate that an attacker has identified working credentials, even though no access token was issued and no successful sign-in was recorded. The application metadata in the sign-in record can provide an initial indicator.

Proofpoint recommends treating these patterns as potential signs of client ID spoofing.  Those credentials could then be tested through a real application or used in phishing, MFA-targeting or other account-compromise attempts.

This OAuth client ID spoofing exposes a digital identity security problem in which an authentication system can deny access while still revealing useful information about the accounts and credentials being tested.

Users must analyze error code patterns, incomplete application metadata, large numbers of client IDs, and requests targeting many accounts from related infrastructure.

Related Posts

Article Topics

 |   |   |   | 

Latest Biometrics News

 

Meta’s WhatsApp age-check trial faces challenge from India’s digital ID plans

Meta is testing age confirmation on WhatsApp ahead of India’s Digital Personal Data Protection (DPDP) Act, but draft implementation rules…

 

Thai regulators propose linking Roblox to national digital ID for age assurance

While it has surely been a busy few months for compliance teams at every large social media company, a special…

 

Sri Lanka digital ID rollout advances as procurement nears completion

Sri Lanka’s digital identity (SL-UDI) program is moving toward a phased rollout as the Indian government finalizes procurement of the…

 

Bangladesh is assembling the trust infrastructure needed for a digital economy

Bangladesh is assembling the foundational layers of a digital economy through a combination of national digital identity, trusted credentials, interoperable…

 

France ruling on social media age check law has major implications for EU, big platforms

France’s Constitutional Council has declared that legislation limiting social media to kids under 15 constitutes “a disproportionate infringement of freedom…

 

Australia’s eSafety boss seeks easier access to documents in ongoing battle with social media

Australia continues to try and find ways to make social media giants follow its social media minimum age (SMMA) law….

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events