<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>cctbp</title><description>Security research focused on authentication and identity vulnerabilities in modern web applications.</description><link>https://blog.cctbp.com/</link><item><title>The Local Lab Blueprint: Building an Isolated, Scriptable Interception Lab</title><link>https://blog.cctbp.com/posts/26-05-29-local-lab-blueprint/</link><guid isPermaLink="true">https://blog.cctbp.com/posts/26-05-29-local-lab-blueprint/</guid><description>A reproducible, containerized interception lab for auth-flow research — mitmproxy, Docker, and browser session containerization, built to be torn down and rebuilt in under five minutes.</description><pubDate>Fri, 29 May 2026 04:00:00 GMT</pubDate></item><item><title>OAuth Authorization Code Interception: The Flow, the Seam, and What Your Logs Actually Show</title><link>https://blog.cctbp.com/posts/26-05-22-oauth-authorization-code-interception/</link><guid isPermaLink="true">https://blog.cctbp.com/posts/26-05-22-oauth-authorization-code-interception/</guid><description>Authorization code interception end-to-end: what the attack looks like, where the seam is, and what it produces in logs. Reproducible against FlawedToken.</description><pubDate>Fri, 22 May 2026 04:00:00 GMT</pubDate></item><item><title>The Gap Nobody Talks About: From &quot;OAuth Is Attackable&quot; to &quot;Here&apos;s the Proof&quot;</title><link>https://blog.cctbp.com/posts/the-gap-nobody-talks-about/</link><guid isPermaLink="true">https://blog.cctbp.com/posts/the-gap-nobody-talks-about/</guid><description>A controlled lab environment for auth-flow attack chains has never existed in any usable form. This series is about closing that gap.</description><pubDate>Sat, 16 May 2026 08:00:00 GMT</pubDate></item></channel></rss>