Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Authentication bypass via OAuth implicit flow (Apprentice) · 🇬🇧
- PortSwigger — Stealing OAuth access tokens via a proxy page (Apprentice) · 🇬🇧
- PortSwigger — Forced OAuth profile linking (Practitioner) · 🇬🇧
- PortSwigger — OAuth account hijacking via redirect_uri (Practitioner) · 🇬🇧
- PortSwigger — SSRF via OpenID dynamic client registration (Practitioner) · 🇬🇧
- PortSwigger — Stealing OAuth access tokens via an open redirect (Practitioner) · 🇬🇧
Curated resources
HTB machines practicing OAuth Authentication Vulnerabilities (1)
PortSwigger labs practicing OAuth Authentication Vulnerabilities (6)
TryHackMe rooms practicing OAuth Authentication Vulnerabilities (1)
← Back to the full glossary Last updated: 2026-08-17