Skip to main content
This page aggregates cross-platform resources to practice OAuth Authentication Vulnerabilities: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 8 challenges across 3 platforms — 1 HackTheBox · 6 PortSwigger · 1 TryHackMe. 1 with a Spanish writeup, 1 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwiggerAuthentication bypass via OAuth implicit flow (Apprentice) · 🇬🇧
  2. PortSwiggerStealing OAuth access tokens via a proxy page (Apprentice) · 🇬🇧
  3. PortSwiggerForced OAuth profile linking (Practitioner) · 🇬🇧
  4. PortSwiggerOAuth account hijacking via redirect_uri (Practitioner) · 🇬🇧
  5. PortSwiggerSSRF via OpenID dynamic client registration (Practitioner) · 🇬🇧
  6. PortSwiggerStealing OAuth access tokens via an open redirect (Practitioner) · 🇬🇧

Curated resources

HTB machines practicing OAuth Authentication Vulnerabilities (1)

PortSwigger labs practicing OAuth Authentication Vulnerabilities (6)

TryHackMe rooms practicing OAuth Authentication Vulnerabilities (1)


Back to the full glossary Last updated: 2026-08-17