webPromedium

DevRelay — Open Redirect in OAuth Authorization

hackadvisor

Task: DevRelay API platform uses OAuth 2.0 Authorization Code flow with no redirect_uri validation, plus an admin bot that visits user-submitted URLs. Solution: Craft malicious OAuth authorize URL redirecting the admin's auth code to a Request Bin, exchange the code for an access token, and access /api/admin/secrets.

$ ls tags/ techniques/
admin_bot_exploitationoauth_redirect_uri_open_redirectauthorization_code_interceptionrequest_bin_exfiltrationoauth_token_exchange

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups