{"repo":"cyberark/oauth-hunter","free":true,"listed":false,"github":"https://github.com/cyberark/oauth-hunter","clone":"git clone https://github.com/cyberark/oauth-hunter.git","description":"A security research tool designed to intercept and analyze OAuth requests.","language":"Python","stars":10,"topics":["mitmproxy","oauth","oauth-security","oauth2","penetration-testing-tools","security-tools","vulnerability-scanners","oauth-misconfiguration"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"oauth-hunter [![GitHub release][release-img]][release] [![License][license-img]][license] oauth-hunter is a powerful tool designed for intercepting and analyzing OAuth requests using mitmproxy. It captures OAuth requests and performs comprehensive testing on the redirect uri parameter, evaluating it against a variety of scenarios to identify potential vulnerabilities. This allows users to ensure the robustness of their OAuth implementations and safeguard against common security issues. In addition to its current capabilities, we are actively working on expanding the tool's functionality to include testing to the state parameter, among other enhancements. This ongoing development aims to provide a more thorough analysis of OAuth implementations, ensuring robust security and resilience against common vulnerabilities. The tool was published as part of the \"How Secure Is Your OAuth? Insights from 100 Websites\" research https://www.cyberark.com/resources/threat-research-blog/how-secure-is-your-oauth-insights-from-100-websites. --- Table of Contents - Deployment - Run from source - Usage - Burp Suite Integration - Menu - Contributing - License - Share Your Thoughts and Feedback --- Deployment You will need the following installed: python 3.x pip3 Run from source Clone the repository: git clone https://github.com/cyberark/oauth-hunter.git Install module dependencies. (You may prefer to do this within a Virtual Environment) cd ./oauth-hunter pip3 install -r requirements.txt Run: pyth","default_branch":null,"files":null,"tree":[],"storefront":"/r/cyberark","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cyberark/oauth-hunter/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}