Link Search Menu Expand Document

recon on


authentication bypass via oauth implicit flow

Intercept /authenticate endpoint and cahnge the client_id to the email address of the victim

Forced oauth profile linking

Do a login using social media. Intercept /oauth-linking endpoint, steal the token and iframe it to the victim

<iframe src=""></iframe>

Then relogin using social media

account hijacking

login using auth. Login again, intercept and chang the redirect_uri. Get the token from the logs use

<iframe src=""></iframe>

and deliver to victim. Relogin as victim.

stealing token via open redirect

see portswigger

40397ac9 (main) : 2023-01-11T20:40:16+01:00