AmirMohammad Safari's banner
AmirMohammad Safari's profile picture

AmirMohammad Safari

@AmirMSafari8,132 subscribers

Part-time bug hunter, full-time thinker of thoughts nobody asked for

Shorts

We’ve created a lab to demonstrate how an OAuth token can be leaked using a referrer policy override. Check out the article and try the lab here

We’ve created a lab to demonstrate how an OAuth token can be leaked using a referrer policy override. Check out the article and try the lab here

27,523 次观看

In our NahamCon talk, we demonstrated how punycode email addresses can impact OAuth implementations. MySQL + GitLab OAuth by default can lead to zero-click account takeover. 🔍 Check out the demo app here:

In our NahamCon talk, we demonstrated how punycode email addresses can impact OAuth implementations. MySQL + GitLab OAuth by default can lead to zero-click account takeover. 🔍 Check out the demo app here:

23,153 次观看

Videos

没有更多内容可加载