The Burp Suite User Forum will be discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Centre. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTRE DISCORD

Create new post

Question about OAuth account hijacking via redirect_uri

mhg | Last updated: Sep 18, 2024 01:20PM UTC

I was working on this lab, when i found, when you send the malformed request i mean the redirect_uri value --> it immediately sends back you the token --> my Question is should i assume that the lab is skipping the 'permissions' part that a User should consent before the token is sent? this has nothing to do with the Validation of redirect_uri. thanks.

Ben, PortSwigger Agent | Last updated: Sep 19, 2024 01:22PM UTC

Hi, Are you able to clarify the question that you are asking?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.