What would you like added?
Add an article on testing Oauth. Ensure it follows the article standard.
@victoriadrake link is broken, so I leave this one here, I believe it is the correct one atm.
https://github.com/OWASP/wstg/blob/master/template/999.2_Template_Explanation_WSTG-FOO-002.md
Fixed. Tickets were opened before the OTG > WSTG change
Thanks to @garethventon, provided me with the following link to identify prevention mechanisms. This link can help us write out the tests for this testing scenario:
Facebook OAuth Framework Vulnerability
I'm happy to begin some work on this
@hazanasec are you going to be able to tackle this?
@kingthorin I'm about half way through, was slowed down by personal things
No worries, was just checking in. Life happens 馃憤
Please comment if you are still working on this issue, as it has been inactive for 30 days. To give everyone a chance to contribute, we are releasing it to new contributors.
For reference, the IETF described a set of security practices around OAuth2: https://tools.ietf.org/html/draft-ietf-oauth-security-topics-16
Mhm, I provided @hazanasec with that and other guidance links. I believe he has something in store for us, just busy I guess with life.
@hazcod Are you interested in helping with this? :)
@hazanasec would you be able to open up a draft PR so maybe we can chime in on it and push it?
I can review or chime in, but in my opinion I haven't done enough oauth security testing to really author it.
@hazanasec any news?
Most helpful comment
I can review or chime in, but in my opinion I haven't done enough oauth security testing to really author it.