> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth Authentication Vulnerabilities

> Recursos cross-platform para OAuth Authentication Vulnerabilities: máquinas HTB, labs PortSwigger y rooms TryHackMe curados, con writeups validados y skills relacionadas.

# OAuth Authentication Vulnerabilities

Esta página agrega los **recursos para practicar OAuth Authentication Vulnerabilities** de forma cross-platform: máquinas retiradas de Hack The Box, labs de PortSwigger Web Security Academy y rooms de TryHackMe, más recursos curados (HackTricks, PortSwigger, etc.) y skills relacionadas.

## Recursos curados

| Fuente      | Enlace                                                                                   |
| ----------- | ---------------------------------------------------------------------------------------- |
| PortSwigger | [https://portswigger.net/web-security/oauth](https://portswigger.net/web-security/oauth) |

## Máquinas HTB que practican OAuth Authentication Vulnerabilities (1)

| Máquina                                    | SO    | Dificultad                                       |
| ------------------------------------------ | ----- | ------------------------------------------------ |
| [Oouch](/htb/machines/linux/dificil/oouch) | Linux | <span className="dbadge dbadge-hard">HARD</span> |

## Labs PortSwigger que practican OAuth Authentication Vulnerabilities (6)

| Lab                                                                                                                                  | Dificultad                                                 | Topic                | Oficial                                                                                                          |
| ------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------- | -------------------- | ---------------------------------------------------------------------------------------------------------------- |
| [Authentication bypass via OAuth implicit flow](/portswigger/labs/oauth/oauth-authentication-bypass-via-oauth-implicit-flow)         | <span className="dbadge dbadge-easy">APPRENTICE</span>     | OAuth Authentication | [Abrir](https://portswigger.net/web-security/oauth/lab-oauth-authentication-bypass-via-oauth-implicit-flow)      |
| [Stealing OAuth access tokens via a proxy page](/portswigger/labs/oauth/oauth-stealing-oauth-access-tokens-via-a-proxy-page)         | <span className="dbadge dbadge-easy">APPRENTICE</span>     | OAuth Authentication | [Abrir](https://portswigger.net/web-security/oauth/lab-oauth-stealing-oauth-access-tokens-via-a-proxy-page)      |
| [Forced OAuth profile linking](/portswigger/labs/oauth/oauth-forced-oauth-profile-linking)                                           | <span className="dbadge dbadge-medium">PRACTITIONER</span> | OAuth Authentication | [Abrir](https://portswigger.net/web-security/oauth/lab-oauth-forced-oauth-profile-linking)                       |
| [OAuth account hijacking via redirect\_uri](/portswigger/labs/oauth/oauth-account-hijacking-via-redirect-uri)                        | <span className="dbadge dbadge-medium">PRACTITIONER</span> | OAuth Authentication | [Abrir](https://portswigger.net/web-security/oauth/lab-oauth-account-hijacking-via-redirect-uri)                 |
| [SSRF via OpenID dynamic client registration](/portswigger/labs/oauth/openid-oauth-ssrf-via-openid-dynamic-client-registration)      | <span className="dbadge dbadge-medium">PRACTITIONER</span> | OAuth Authentication | [Abrir](https://portswigger.net/web-security/oauth/openid/lab-oauth-ssrf-via-openid-dynamic-client-registration) |
| [Stealing OAuth access tokens via an open redirect](/portswigger/labs/oauth/oauth-stealing-oauth-access-tokens-via-an-open-redirect) | <span className="dbadge dbadge-medium">PRACTITIONER</span> | OAuth Authentication | [Abrir](https://portswigger.net/web-security/oauth/lab-oauth-stealing-oauth-access-tokens-via-an-open-redirect)  |

## Rooms TryHackMe que practican OAuth Authentication Vulnerabilities (1)

| Room                                                           | Dificultad                                         | Tipo        | Acceso | Oficial                                                  |
| -------------------------------------------------------------- | -------------------------------------------------- | ----------- | ------ | -------------------------------------------------------- |
| [OAuth Vulnerabilities](/tryhackme/rooms/oauthvulnerabilities) | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🔵 VIP | [Abrir](https://tryhackme.com/room/oauthvulnerabilities) |

***

← [Volver al glosario completo](/glosario)

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"DefinedTerm","name":"OAuth Authentication Vulnerabilities","termCode":"oauth","inLanguage":"es","url":"https://rootea.es/skills/oauth","inDefinedTermSet":{"@type":"DefinedTermSet","name":"Glosario táctico de pentesting","url":"https://rootea.es/glosario"}}`}
</script>

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"ItemList","name":"Máquinas HTB que practican OAuth Authentication Vulnerabilities","numberOfItems":1,"itemListElement":[{"@type":"ListItem","position":1,"url":"https://rootea.es/htb/machines/linux/dificil/oouch","name":"Oouch"}]}`}
</script>

*Última actualización: 2026-06-07*
