Web Hack List

Collected research

CSS Data Exfiltration to Steal OAuth Token

Combines an OAuth redirect with CSS injection on a page where an advertising script reflects the URL token into a DOM attribute. Imported styles test that attribute and signal matches through background requests; the writeup diagnoses cascade failures and increases selector specificity between rounds to continue extracting the token.

Record

Researcher
Amirmohammad Safari and Yashar Shahinzadeh
Published by
Voorivex
Date
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Amirmohammad Safari and Yashar Shahinzadeh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .