All tags
— Tag · oauth 10 / 10
  1. 2026 · 03 · 21

    Story of Abusing a Fully Secured redirect_uri in an OAuth Flow

  2. 2026 · 02 · 10

    When Two Parsers Disagree: Exploiting Query String Differentials for XSS

  3. 2026 · 02 · 03

    Shaking the MCP Tree: a security deep dive

  4. 2025 · 12 · 07

    DOM XSS to Account Takeover: not-so-dirty dancing in a GIS SDK

  5. 2025 · 06 · 01

    Puny-Code, 0-Click Account Takeover

  6. 2025 · 05 · 06

    Stealing oAuth Token via Referrer Policy Override

  7. 2025 · 02 · 15

    CSS Data Exfiltration to Steal OAuth Token

  8. 2024 · 11 · 22

    OAuth Non-Happy Path to ATO

  9. 2024 · 10 · 11

    Drilling the redirect_uri in OAuth

  10. 2023 · 11 · 17

    Hijacking OAuth Code via Reverse Proxy for Account Takeover