OAUTH Flow Exploitation

Identify and exploit logical flaws in OAuth 2.0 and OpenID Connect workflows. Use this skill when testing "Sign in with Google/Facebook/Apple" features, focusing on Authorization Code interception, Implicit flow token leakage, standard CSRF bypassing via missing `state` parameters, and redirect logic flaws.

ShulkwiSEC 7316c20 3 files · 17.3 KB Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/oauth-flow-exploitation commit 7316c203d8

Frequently asked questions

npx skillmds add shulkwisec/oauth-flow-exploitation