Back to directory
WRITEUP #648

How OAuth Implicit Flow Led To Hundreds Of User Accounts Being Accessed?

OAuth
by@gouri_sufyan(Sufiyan Gouri)
Program
-
Published
Dec 13, 2023
Added to HackDex
Feb 1, 2024
Read Full Writeuphttps://payatu.com/blog/how-oauth-implicit-flow-led-to-hundreds-of-user-accounts-being-accessed/
RELATED WRITEUPS
How I Got $250 For My Second Bug on HackerOne
OAuthSession expiration issue
AI Under Siege: Discovering and Exploiting Vulnerabilities
AI / LLMAI
Stealing First Party Access Token of Facebook Users: Meta Bug Bounty
OAuthAccount takeover
Over 1 Million websites are at risk of sensitive information leakage - XSS is dead. Long live XSS
XSSOAuth
Self XSS + Login CSRF + OAuth = Account Takeover
Auth BypassAccount takeover

Built with ❤️ by Shubham Rawat