Tag: flawedtoken
All the articles with the tag "flawedtoken".
-
Redirect URI Manipulation: Stealing the Authorization Code at the Door
The redirect_uri is the load-bearing control in the OAuth authorization code flow, and it fails quietly. A red-team walkthrough of manipulating it, reproduced against a real vulnerable client in the interception lab.
-
OAuth Authorization Code Interception: The Flow, the Seam, and What Your Logs Actually Show
Authorization code interception end-to-end: what the attack looks like, where the seam is, and what it produces in logs. Reproducible against FlawedToken.