BigHugger
sk Skill · mukul975

testing-oauth2-implementation-flaws

Tests OAuth 2.0 and OpenID Connect implementations for authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass, using Burp Suite Professional and the EsPReSSO extension to probe the authorization server, client, and token handling. Use when assessing OAuth2/OIDC flows or SSO systems for misconfigurations enabling account takeover.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
pythonPythontoken-securityauthenticationredirect-urioidcoauth2api-security
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0.0
Licence
Apache-2.0
Host stars
33k
Host language
Python