Maintenance in progress: we are indexing a large batch of new skills. Some pages may load slowly or briefly show no results. Nothing is lost, and everything is back to normal within the hour.

OAUTH State Parameter Abuse

Identify and exploit logic flaws in OAuth implementations, focusing specifically on the absence or improper validation of the `state` parameter, which leads to Cross-Site Request Forgery (CSRF) and account takeover (ATO).

ShulkwiSEC 686033e 3 files · 11.9 KB Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/oauth-state-parameter-abuse commit 686033eb42

Frequently asked questions

npx skillmds add shulkwisec/oauth-state-parameter-abuse