Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Hacking OAuth 2.0 for Fun and Profit

Bugcrowd via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course explains OAuth 2.0 flows and demonstrates attacks on OAuth integrations, including token and code theft, CSRF, and token impersonation. It uses a case study and proof of concept to illustrate the attack workflow.

Syllabus

Intro
About Me
Agenda
HISTORY OF OAuth
OAuth 2.0 BASICS
HOW OAuth 2.0 WORKS?
AUTHORIZATION CODE GRANT
IMPLICIT GRANT
WHERE OAuth 2.0 IS USED?
ATTACKS ON OAuth 2.0 INTEGRATIONS
TOKEN STEALING - What we do?
TOKEN STEALING - Secret Methodology
Case Study
PROOF OF CONCEPT
CODE STEALING - What we do?
CODE STEALING-Secret Methodology
CSRF - What we do?
CODE STEALING - Secret Methodology
ATTACK WORKFLOW
TOKEN IMPERSONATION - What we do?
TOKEN IMPERSONATION. Secret Methodology
CONCLUSION

Taught by

Bugcrowd

Reviews

Start your review of Hacking OAuth 2.0 for Fun and Profit

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.