The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Stealing OAuth access tokens via an open redirect lab

Joanna | Last updated: May 18, 2024 03:54PM UTC

Is it possible to get invalid access tokens in the access log? I've been stuck on this lab for hours and got two access tokens, both rejected upon submission. Following the tutorial over and over, cannot figure out what I'm doing wrong... Thanks in advance!

Dominyque, PortSwigger Agent | Last updated: May 20, 2024 08:28AM UTC