Back to directory
WRITEUP #4016

OAuth Misconfiguration Leads to Full Account takeover

OAuthClickjackingCSRFAccount takeover
by@boomneroli(Yasser Mohammed)
Program
-
Published
Feb 13, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://neroli.medium.com/oauth-misconfiguration-leads-to-full-account-takeover-22b032cb6732
RELATED WRITEUPS
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover
AI Under Siege: Discovering and Exploiting Vulnerabilities
AI / LLMAI
Stealing First Party Access Token of Facebook Users: Meta Bug Bounty
OAuthAccount takeover
Self XSS + Login CSRF + OAuth = Account Takeover
Auth BypassAccount takeover
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover

Built with ❤️ by Shubham Rawat