TryHackMe's Web App PenTest -- OAuth Vulnerabilities: https://tryhackme.com/r/room/oauthvul...
00:00 Introduction
00:38 Key concepts
09:57 OAuth Grant Types
10:16 Authorization Code Grant
12:21 Implicit Grant
13:47 Resource Owner Password Credentials Grant
14:53 Client Credentials Grant
16:00 How OAuth work flows
19:05 Authorization Request
22:09 Authentication & Authorization
24:51 Token Reques t
26:04 Token Response
28:03 Identifying the OAuth services
28:33 Detecting OAuth Implementation
29:25 Identify OAuth frameworks
32:44 Stealing OAuth token
40:29 CSRF in OAuth
53:17 Implicit Grant Flow
01:06:18 Other vulnerabilities
01:07:48 Evolution of OAuth 2.1