— Tag · oauth
10 / 10
-
2026 · 03 · 21
Story of Abusing a Fully Secured redirect_uri in an OAuth Flow
-
2026 · 02 · 10
When Two Parsers Disagree: Exploiting Query String Differentials for XSS
-
2026 · 02 · 03
Shaking the MCP Tree: a security deep dive
-
2025 · 12 · 07
DOM XSS to Account Takeover: not-so-dirty dancing in a GIS SDK
-
2025 · 06 · 01
Puny-Code, 0-Click Account Takeover
-
2025 · 05 · 06
Stealing oAuth Token via Referrer Policy Override
-
2025 · 02 · 15
CSS Data Exfiltration to Steal OAuth Token
-
2024 · 11 · 22
OAuth Non-Happy Path to ATO
-
2024 · 10 · 11
Drilling the redirect_uri in OAuth
-
2023 · 11 · 17
Hijacking OAuth Code via Reverse Proxy for Account Takeover