Burp Suite User Forum

Create new post

Forced OAuth profile linking

Dimple | Last updated: Feb 06, 2021 07:51AM UTC

I am unable to get to the admin tab even after following the solutions. I have captured the code using intercept and using iframe tag to deliver it to the victim's server. I did logout and then tried to log in using social media account and there I was expecting the admin tab to appear but it is not working the same way. Please advise.

Ben, PortSwigger Agent | Last updated: Feb 08, 2021 04:02PM UTC

Hi, To confirm, have you dropped the GET /oauth-linking?code request, clicked the back button in your browser when you observe the Burp error warning of the dropped request and then logged out of the blog?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.