Offensive OAUTH

OAuth 2.0 attack checklist: authorization code interception, redirect_uri bypass, CSRF on OAuth flow, state parameter abuse, open redirector chaining, token leakage via Referer, PKCE bypass, and scope escalation. Use when testing OAuth implementations in web apps or bug bounty. Use only for authorized security research, training, or assessment.

26zl 49953aa 15.1 KB Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/offensive-oauth commit 49953aaeb0

Frequently asked questions

npx skillmds@latest add 26zl/offensive-oauth