Web OAUTH

Attack OAuth 2.0 / OIDC / SSO flows for account takeover. Load on "Login with Google/GitHub", /authorize, /callback, redirect_uri, state, code/token params, SAML/OIDC SSO. Signals: OAuth endpoints, redirect_uri handling, missing state, implicit flow, pre-account-linking.

NoorQureshi 43584ba 2.0 KB Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/web/web-oauth commit 43584ba383

Frequently asked questions

npx skillmds@latest add noorqureshi/web-oauth