Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Unveiling Oauth for Bug Bounty Hunting
Rating: 4.4 out of 5(17 ratings)
591 students

Unveiling Oauth for Bug Bounty Hunting

learn about oauth ,its misconfigurations and understand oauth attack in real world scenerios
Created byAnurag Verma
Last updated 11/2023
English
English [Auto],

What you'll learn

  • What is oauth?
  • Types of oauth?
  • Oauth Misconfigurations with proper explanations
  • Learning different attacks possible in oauth
  • Learn chaining oauth with other vulnerabilities like CSRF,HTML injection
  • Business logic misconfigurations with oauth
  • Special case of bypassing CORS policy and finally making it to account takeover

Course content

5 sections14 lectures1h 48m total length
  • Author Introduction0:43

    Author introduction

  • Introduction1:22

    Explore OAuth for bug bounty hunting by introducing types of auth, how OAuth works, common OAuth misconfigurations, demonstrations, live cases, Postman workflows, and business logic misconfigurations.

  • Introduction to Oauth6:41

    Learn how OAuth enables third-party apps to access user resources without exposing credentials. Identify the four entities: the user, resource owner, client, and authorization server, and how they work together.

Requirements

  • Good to know basics of burpsuite,postman,some basics of development like HTML,JS
  • If you haven't explored any of those mentioned above then no issue you can first learn basics of them then you are ready for the demonstrations

Description

OAuth is one the most important topics nowadays if you study web applications penetration testing or API security testing or android security testing then OAuth is one of the most common topics, it is popularly used in almost every application, and vulnerabilities like account takeover are found in oauth misconfigurations,

if you don't know how to go for oauth testing then this course is for you, you will be able to learn different types of attacks possible with oauth with respective misconfiguration and will learn how chaining can be done in oauth with other vulnerabilities, I have demonstrated the oauth misconfiguration using portswigger labs and also discussed the live finding from a bug bounty programme, you can also find similar issues on your programme as well

This is a short course, in this course, you will be going to learn =>


  • What is Oauth?

  • Types of Oauth?

  • How does Oauth work?

  • What are oauth misconfigurations?

  • Demonstrations of account takeovers on lab and live cases

  • Analysing oauth flow from developers docs using Postman

  • Analysing how to bypass some of the restrictions and chaining oauth with other vulnerabilities

  • Understanding more business logic misconfiguration collected from various reports and articles.


Use the tutorials for education purposes only don't misuse them in the real world



Thanks

Who this course is for:

  • Ethical Hackers
  • Bug Bounty Hunters
  • Security Engineers
  • Red Teamers
  • Developers
  • IT analysts
  • Security Enthusiasts