Collected research
Hijacking OAuth Code via Reverse Proxy for Account Takeover
Shows an OAuth authorization code leaking through a same-origin image proxy. A state-controlled redirect retains an accepted callback prefix while traversing into the proxy route, which forwards the appended code to an attacker-controlled endpoint; intermediate requests illustrate how a constrained fetch feature becomes a credential-leak sink.
Record
- Researcher
- Omid Rezaei
- Published by
- Voorivex
- Date
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Omid Rezaei, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .