What problem does it solve?
OAuth vulnerabilities are high-severity flaws that lead to account takeover, session theft, and authentication bypass, but most security testers lack a structured, field-validated methodology to identify them consistently during bug bounties and penetration tests.
Core Features & Use Cases
- Proven Bug Bounty Techniques: Built from 19 public, verified bug bounty reports with real-world payloads and disclosed case studies from 2020-2024.
- Comprehensive Testing Workflow: Step-by-step methodology covering redirect_uri validation bypasses, state/nonce CSRF testing, mobile deep link exploitation, referrer leakage detection, and client credential misconfiguration checks.
- Defense Bypass Guidance: Specific bypass techniques for common security controls like exact-match redirect_uri whitelists, PKCE enforcement, and nonce validation.
- Use Case: Ideal for bug bounty hunters, penetration testers, and security teams assessing platforms with social login, SSO integrations, OAuth authorization servers, and mobile apps with OAuth flows to find critical, high-payout vulnerabilities.
Quick Start
Use the hunt-oauth skill to test the target platform's OAuth authorization and token endpoints for critical vulnerabilities including redirect_uri bypasses, state parameter CSRF, and token leakage.