vulns.co
/
GKData.io MCP

Back to Playbooks

OAuth & SSO Misconfiguration

Abuse loose redirect and state handling in OAuth flows to steal tokens and take over accounts.

Tags: oauth, sso, openid, auth

Level: advanced

Method

  1. Map the flow

    Capture the full authorization request: client_id, redirect_uri, response_type, scope, and state. Note whether it's implicit (token in fragment) or code flow.

    Tools: Burp Suite

  2. Attack redirect_uri

    Test path traversal, subdomain wildcards, open-redirect chains, and appended parameters to exfiltrate the code/token to an attacker-controlled host.

  3. Break state / CSRF

    Remove or reuse the state parameter to test login CSRF and account linking (attach your social login to the victim's account).

  4. Steal via referer / leaks

    Check if the code/token leaks through Referer headers to third-party resources on the callback page.

Field notes

  • A redirect_uri that allows any subdomain + one open redirect on a subdomain = token theft.
  • Pre-account-takeover: register with a victim's email before they do via SSO.

References