You asked for something about OAuth — we did.
Here is a mindmap about hacking OAuth 2.0. We tried to cover all possible ways even with low impact.
Our inspiration was http://homakov.blogspot.com/search?q=oauth
Thanks to @homakov for outstanding articles.
#BugBountyTip #CyberSecurity #BugBounty
Also check this:
Introduction: http://medium.com/a-bugz-life/the-wondeful-world-of-oauth-bug-bounty-edition-af3073b354c1 …
Our mindmaps in XMind http://github.com/hackerscrolls/SecurityTips/tree/master/MindMaps …
Android Intent trick:
Race Condition in OAuth: http://hackerone.com/reports/55140
Twitter OAuth bug: http://hackerone.com/reports/110293
Leaking CODE: http://hackerone.com/reports/314814
You can follow @hackerscrolls.
Tip: mention @threader_app on a Twitter thread with the keyword “compile” to get a link to it.
Enjoy Threader? Sign up.
Since you’re here...
... we’re asking visitors like you to make a contribution to support this independent project. In these uncertain times, access to information is vital. Threader gets 1,000,000+ visits a month and our iOS Twitter client was featured as an App of the Day by Apple. Your financial support will help two developers to keep working on this app. Everyone’s contribution, big or small, is so valuable. Support Threader by becoming premium or by donating on PayPal. Thank you.