Tag: mitmproxy
All the articles with the tag "mitmproxy".
-
Redirect URI Manipulation: Stealing the Authorization Code at the Door
The redirect_uri is the load-bearing control in the OAuth authorization code flow, and it fails quietly. A red-team walkthrough of manipulating it, reproduced against a real vulnerable client in the interception lab.
-
The Local Lab Blueprint: Building an Isolated, Scriptable Interception Lab
A reproducible, containerized interception lab for auth-flow research — mitmproxy, Docker, and browser session containerization, built to be torn down and rebuilt in under five minutes.