Joe Bollen
banner
joe-bollen.bsky.social
Joe Bollen
@joe-bollen.bsky.social
AI and Security Research
We just released our own :) -> ctf.fondu.ai
October 21, 2023 at 4:39 PM
Big 3:

1. Improper Implementation of Implicit Grant

2. Flawed CSRF Protection

3. Flawed Redirect_URI Validation

More difficult:

4. Stealing Codes via a Proxy Page

5. Scope Upgrade of Authorization Code Flow
October 20, 2023 at 7:23 PM
👋
October 20, 2023 at 7:18 PM