<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    
    <title>surajdisoja.me</title>
    
    
    <description>This website is a virtual proof that I&apos;m awesome</description>
    
    <link>https://blog.surajdisoja.me/</link>
    <atom:link href="https://blog.surajdisoja.me/feed.xml" rel="self" type="application/rss+xml" />
    
    
      <item>
        <title>OAuth and PostMessage</title>
        <description>
          Chaining misconfigurations for your access token. - 
          Tl;dr: An OAuth misconfiguration was discovered in the redirect_uri parameter at the target’s OAuth IDP at https://app.target.com/oauth/authorize, which allowed attackers to control the path of the callback endpoint using the...
        </description>
        <pubDate>Mon, 21 Feb 2022 00:00:00 -0500</pubDate>
        <link>https://blog.surajdisoja.me/2022-02-21-oauth-postmessage-misconfig/</link>
        <guid isPermaLink="true">https://blog.surajdisoja.me/2022-02-21-oauth-postmessage-misconfig/</guid>
      </item>
    
      <item>
        <title>Watch your requests!</title>
        <description>
          Open redirection to account takeover - 
          Recently, while testing a web application, I discovered multiple vulnerabilities that on chaining together could have allowed anyone to take over the Victim account. The affected company name is interchanged...
        </description>
        <pubDate>Mon, 05 Oct 2020 00:00:00 -0400</pubDate>
        <link>https://blog.surajdisoja.me/2020-10-05-open-redir-to-ato/</link>
        <guid isPermaLink="true">https://blog.surajdisoja.me/2020-10-05-open-redir-to-ato/</guid>
      </item>
    
  </channel>
</rss>
