OAUTH Misconfigurations

Resources

  1. OAuth2.0 Protocol Code Flow with PKCE Explained in Arabic: https://www.youtube.com/watch?v=_NNPKyAlaIw

  2. Modern Guide - What is OAuth 2.0 and How Does It Work: https://fusionauth.io/articles/oauth/modern-guide-to-oauth

  3. OAuth 2.0 flows explained in GIFs: https://www.youtube.com/watch?v=ZDuRmhLSLOY

  4. Official Docs: https://oauth.net/2/

  5. YouTube: OAuth2.0 Protocol Code Flow with PKCE Explained | oauth2.0 Ψ΄Ψ±Ψ­

Mind map

https://pbs.twimg.com/media/EZ1WqmcXYAAqwSH?format=jpg&name=900x900

Top OAuth reports from HackerOne:

  1. Shopify Stocky App OAuth Misconfiguration to Shopify - 514 upvotes, $0

  2. Stealing Facebook OAuth Code Through Screenshot viewer to Rockstar Games - 193 upvotes, $0

  3. CSRF on Periscope Web OAuth authorization endpoint to X (Formerly Twitter) - 66 upvotes, $0

  4. Mattermost Server OAuth Flow Cross-Site Scripting to Mattermost - 38 upvotes, $900

  5. Stealing Users OAUTH Tokens via redirect_uri to BOHEMIA INTERACTIVE a.s. - 38 upvotes, $0

  6. Race Conditions in OAuth 2 API implementations to Internet Bug Bounty - 37 upvotes, $0

Last updated