Adding TRR for Authorization Code Phishing - #21
Conversation
|
Sorry for the delay. I approved the workflow and looks like there are some linter changes that need addressed. Looks mostly like line-wrapping and a few inline-urls. |
vanvleeta
left a comment
There was a problem hiding this comment.
Excellent first draft! Thank you for the submission!
dumpst3rfir3
left a comment
There was a problem hiding this comment.
I agree with other comments, great work! I'm not sure I had much to add to what's already been said, but I left a couple of comments in there.
|
I think I fixed all of the issues with this new commit. If there are more issues please let me know and I will be happy to fix! Thanks again for the review! |
mjwhitta
left a comment
There was a problem hiding this comment.
Just a couple small things. Ultimately this looks really good!
dumpst3rfir3
left a comment
There was a problem hiding this comment.
LGTM. I had some nit-picky comments/questions, but feel free to ignore.
|
Really sorry for the long delay, btw. |
Co-authored-by: vanvleeta <vanvleet@gmail.com>
Co-authored-by: vanvleeta <vanvleet@gmail.com>
08cfcbb to
32dbedf
Compare
|
Fresh batch of updates. Thanks for the feedback! If you see any other issues, please let me know! |
|
I think this LGTM, but I believe @vanvleeta might have something to say about the DDM. I can't tell if it was made with the same software he typically uses (arrows?). If he approves, then I will also approve. |
vanvleeta
left a comment
There was a problem hiding this comment.
Looking great! Last few suggestions!
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
vanvleeta
left a comment
There was a problem hiding this comment.
Looks awesome, ready to go IMHO!
Hello,
This pull request adds a Technique Research Report (TRR) covering OAuth Authorization Code Phishing, including documentation of the ConsentFix procedure within Microsoft Entra ID environments. The report outlines the mechanics of the authorization code flow and describes how attackers can abuse redirect behavior to obtain authorization codes and redeem them for access tokens.
This is my first contribution to the repository, so please let me know if there are any formatting issues or changes that would improve the submission. I appreciate any feedback from the maintainers.