Web Level 4 150 points

Web-28. Hijacking an OAuth Authorization Code

Mission

This OAuth 2.0 authorization provider offers a login flow, but its redirect_uri validation may be weak. Investigate whether an authorization code can be hijacked to obtain an admin-level access token.

#web#oauth

Clear it in 3 steps

Not started
  1. Start the environment

  2. Investigate the target

  3. Submit the flag