The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Information exposure in the "interaction" endpoint of the oauth servers

harel | Last updated: Feb 03, 2022 03:58PM UTC

"OAuth authentication" labs. Making a request to the OAuth server like that: https://oauth-endpoint/interaction/$$$" where '$$$' can be anything. That yields: SessionNotFound: invalid_request at *** (***) at *** (***) at *** (***) I only checked two labs.

Ben, PortSwigger Agent | Last updated: Feb 04, 2022 09:16AM UTC