cyber-testing-oauth2-implementation-flaws - Test OAuth2 and OIDC Implementation Flaws
Tests OAuth 2.0 and OpenID Connect implementations for redirect URI, CSRF, token handling, scope, and PKCE security flaws.
Tags
Updated: 2026-10-03Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Discover OAuth endpoints
- Test redirect URI validation
- Check state parameter protection
- Test PKCE enforcement
- Assess scope escalation
- Evaluate token handling
- Validate ID tokens and nonce
Inputs
- Written authorization
- OAuth provider scope
- Client applications in scope
- Registered test OAuth client
- OAuth grant types
- Authorization server endpoints
- Client ID
- Redirect URI
Outputs
- OAuth endpoint findings
- Redirect URI test results
- CSRF test findings
- PKCE test findings
- Scope escalation findings
- Token handling findings
- OIDC validation findings
Requirements
- Written authorization
- Burp Suite Professional
- Python 3.10 or later
- requests library
- oauthlib library
- Browser developer tools
- OAuth grant type knowledge
