The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Question about OAuth account hijacking via redirect_uri

mhg | Last updated: Sep 18, 2024 01:20PM UTC

I was working on this lab, when i found, when you send the malformed request i mean the redirect_uri value --> it immediately sends back you the token --> my Question is should i assume that the lab is skipping the 'permissions' part that a User should consent before the token is sent? this has nothing to do with the Validation of redirect_uri. thanks.

Ben, PortSwigger Agent | Last updated: Sep 19, 2024 01:22PM UTC