webPromedium
Lab 35 — GateKeeper SSO — Open Redirect via Regex URI Validation
hackadvisor
Task: OAuth 2.0 SSO platform with regex-based redirect_uri validation where dot is unescaped, admin bot visits support ticket URLs. Solution: Bypass redirect_uri regex by replacing dot with dash, capture admin's authorization code via callback tester, exchange for access token to retrieve flag from userinfo endpoint.
$ ls tags/ techniques/
jwtadmin_botoauth2regex_bypassopen_redirectssoopenid_connectredirect_uriauthorization_codecallback_tester
admin_bot_exploitationregex_dot_bypassredirect_uri_validation_bypassoauth_authorization_code_thefttoken_exchange
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 348 — Connectify — IDN Homograph OAuth Open Redirect— hackadvisor
- [web][Pro]Lab 173 — ConnectHub — OAuth Open Redirect via URL Userinfo Bypass— hackadvisor
- [web][Pro]Lab 80 — GateGuard — SQL Injection in Organization Filter API— hackadvisor
- [web][Pro]Lab 303 — DevGateway — Broken Access Control in Admin API— hackadvisor
- [web][Pro]SecretKeeper— hackerlab