ApiDiary's profile picture. Diary API Security, Fuzzing and Debugging related tweets, blogs and thoughts | Managed by bt1wis3(@fasthm00)

API Security Diary

@ApiDiary

Diary API Security, Fuzzing and Debugging related tweets, blogs and thoughts | Managed by bt1wis3(@fasthm00)

API Security Diary reposted

Another round of tests added to identify interesting attack vectors against an OpenID Provider / OAuth2 Authorization Server instance. #appsec #openidconnect #oauth Thanks to @ApiDiary for hints/exchanges 🥰 Thanks to @PhilippeDeRyck for the OIDC/Oauth2 training 🥰

righettod's tweet image. Another round of tests added to identify interesting attack vectors against an OpenID Provider / OAuth2 Authorization Server instance. #appsec #openidconnect #oauth 

Thanks to @ApiDiary for hints/exchanges 🥰

Thanks to @PhilippeDeRyck for the OIDC/Oauth2 training 🥰

#TIP: When testing OpenID Connect or OAuth 2.0 and you got the client_id: Always consider/check the same authentication request as the UserInfo endpoint to retrieve PII information by adding the "claims" parameter! Developers so often use the same authentication URI as UserInfo🔥

ApiDiary's tweet image. #TIP:
When testing OpenID Connect or OAuth 2.0 and you got the client_id:
Always consider/check the same authentication request as the UserInfo endpoint to retrieve PII information by adding the "claims" parameter! Developers so often use the same authentication URI as UserInfo🔥

If you're looking for API News, API Tutorial, Latest/Published API, API Charts & Research, search for APIs, SDK and more! Check out this amazing resource: programmableweb.com

ApiDiary's tweet image. If you're looking for API News, API Tutorial, Latest/Published API, API Charts & Research, search for APIs, SDK and more! Check out this amazing resource:
programmableweb.com

This account does not follow anyone
Loading...

Something went wrong.


Something went wrong.