Hijacking OAuth Code via Reverse Proxy for Account Takeover
Recon:
The target scope I had selected was fixed to the main application:
1377.targetstaging.app
In the first phase of my narrow recon approach, I utilized various services like Archive, Google, and Yahoo to extract endpoints and different paths.
Ho...
blog.voorivex.team5 min read
asdawd
awdawd
Cool