Web Hack List

Collected research

OAuth 2.0 Redirect URI Validation Falls Short, Literally

The OAuth 2.0 rule to compare redirect_uri by simple string comparison guards only the domain, so appended path-confusion payloads and injected duplicate code parameters still pass validation, at 6 and 10 of 16 major identity providers respectively. Chained with an open redirect or an ad script anywhere on the client site, this leaks the victim's authorization code and yields account takeover.

Record

Researcher
Tommaso Innocenti, Matteo Golinelli, Kaan Onarlioglu, Ali Mirheidari, Bruno Crispo and Engin Kirda
Published by
ACSAC '23
Format
Whitepaper
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Tommaso Innocenti, Matteo Golinelli, Kaan Onarlioglu, Ali Mirheidari, Bruno Crispo and Engin Kirda, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .