LevelUp 0x02 - Hacking OAuth 2.0 For Fun And Profit

แชร์
ฝัง
  • เผยแพร่เมื่อ 8 ม.ค. 2025

ความคิดเห็น • 19

  • @domaincontroller
    @domaincontroller 4 ปีที่แล้ว +5

    03:29 history of oauth 09:11 authorization grant 11:15 example, zoom

  • @So0oMaSB
    @So0oMaSB 4 ปีที่แล้ว +6

    Awesome, thanks!
    Sorry i laughed about this tho ): 7:14

  • @saintsmehfil_oneness
    @saintsmehfil_oneness 4 ปีที่แล้ว +1

    Very nice, Thanks!

  • @Jeffviola
    @Jeffviola 3 ปีที่แล้ว +1

    How do you purchase a subdomain of another company's domain? I think that was possible?

    • @JorgeDiaz-jd6ku
      @JorgeDiaz-jd6ku 2 ปีที่แล้ว

      i didn’t get that either. maybe the company created a subdomain for him to test the poc ?
      sounds like a domain registration site

  • @yusufali_007
    @yusufali_007 6 ปีที่แล้ว +3

    Cool video.... ❤❤❤

  • @hackersguild8445
    @hackersguild8445 5 ปีที่แล้ว +1

    Nice video.:)

  • @bencesarosi7718
    @bencesarosi7718 4 ปีที่แล้ว +12

    Way too long for what it conveys and not very useful to be honest.
    I quit watching it at the 27 minute mark; at that point did it become crystal clear that this slow-paced presentation only discuss more-or-less obvious information.
    When you have the right XSS (or similar) vector, of course you can hijack the OAuth workflow! Why does that need 50 mins to present?
    Wouldn't neessarily consider this hacking OAuth even. For all intents and purposes, OAuth works as designed throughout the whole process. The video is, as far as I went in, rather about perusing a compromised web application for OAuth access. AFAICT something like "Pivoting Web Vulnerabilities into OAuth 2.0 Access" would've been a more appropriate title.
    NOI, but the 27 minutes I spent watching this felt like wasted time.

    • @TalsonHacks
      @TalsonHacks 3 ปีที่แล้ว +3

      Farah Hawa concluded everything he mentioned in just 10 minutes!

  • @smartcontract647
    @smartcontract647 4 ปีที่แล้ว +1

    great!!

  • @sillydadddy
    @sillydadddy 4 ปีที่แล้ว +1

    Thanks 😊

  • @neelpatel2256
    @neelpatel2256 5 ปีที่แล้ว

    leet stuff

    • @ishanpatel8386
      @ishanpatel8386 3 ปีที่แล้ว

      In 2 years, how was your journey in bug bounty?

  • @aadityaprasad8522
    @aadityaprasad8522 4 ปีที่แล้ว

    🤑