OAuth2 Predictable State: Exploitation

Return to Exercise
image of exercise OAuth2 Predictable State: Exploitation

This video requires PentesterLab PRO

GO PRO
Spoiler
OAuth2 Predictable State: Exploitation

In this video, we explore the OAuth2 Predictable State exercise from the Authentication and Authorization badge. We demonstrate how to exploit predictable states in OAuth2 by brute-forcing the state parameter.

video duration icon12:48 number of views icon858