ðŸ–¥ï¸ Challenge / Machine Info
- Platform: pentesterlab
- Name / Title: oauth-redirect
- Difficulty: Medium
- Target OS / Environment: Web
- Key Vulnerability Focus: OAuth parameter poisoning
Walkthrough
- Manipulate redirect_uri OAuth parameter to point to an open redirect page.
- Intercept OAuth auth codes in attacker logs and log in.