🖥️ Challenge / Machine Info

  • Platform: pentesterlab
  • Name / Title: oauth-redirect
  • Difficulty: Medium
  • Target OS / Environment: Web
  • Key Vulnerability Focus: OAuth parameter poisoning

Walkthrough

  1. Manipulate redirect_uri OAuth parameter to point to an open redirect page.
  2. Intercept OAuth auth codes in attacker logs and log in.