Back to directory
WRITEUP #2697

Stealing Google Drive OAuth tokens from Dropbox

CSRFSSRFAccount takeover
by@sivaneshashok(Sivanesh Ashok)
Bounty
1,728
Program
Dropbox
Published
May 17, 2022
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://blog.stazot.com/stealing-google-drive-oauth-tokens-from-dropbox/
RELATED WRITEUPS
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover
Vulnerabilities in Homepage Dashboard
RCESSRF
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Directory Traversal, SQL Injection and Server-Side Request Forgery
SQL InjectionPath traversal
Self-XSS to ATO via Site Features
XSSSelf-XSS

Built with ❤️ by Shubham Rawat