Web Hack List

Collected research

Hijacking OAuth Code via Reverse Proxy for Account Takeover

Shows an OAuth authorization code leaking through a same-origin image proxy. A state-controlled redirect retains an accepted callback prefix while traversing into the proxy route, which forwards the appended code to an attacker-controlled endpoint; intermediate requests illustrate how a constrained fetch feature becomes a credential-leak sink.

Record

Researcher
Omid Rezaei
Published by
Voorivex
Date
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Omid Rezaei, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .