Welcome to OGeek Q&A Community for programmer and developer-Open, Learning and Share
Welcome To Ask or Share your Answers For Others

Categories

0 votes
426 views
in Technique[技术] by (71.8m points)

oauth 2.0 - Encountered a 200 OK response in BurpSuite however I don't know what to do with it, please guide

I recently started bug bounty and I came up with an obstacle. Long story short I manipulated the redirect uri in the oauth/auth field and it returned a 200 OK response. Which shouldn't happen, right?I did this in BurpSuite.

How do I manipulate it more and report this bug if it even counts as one? I would appreciate any help that you can give, thank you.

ORIGINAL request URI:

/o/oauth2/auth?redirect_uri=(some long uri)

MANIPULATED request URI(added the and symbol):

 /o/oauth2/auth?redirect_uri=(some long uri)&facebook.com

与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
Welcome To Ask or Share your Answers For Others

1 Reply

0 votes
by (71.8m points)
等待大神答复

与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
OGeek|极客中国-欢迎来到极客的世界,一个免费开放的程序员编程交流平台!开放,进步,分享!让技术改变生活,让极客改变未来! Welcome to OGeek Q&A Community for programmer and developer-Open, Learning and Share
Click Here to Ask a Question

...