OIDC

Cloud Security

Azure AD / Entra ID Token Theft and Abuse

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

Single Sign-On (SSO) Threats and Hardening

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

SAML vs OIDC: A Security Comparison

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

Breaking OAuth 2.0 and OpenID Connect: Redirect, State, and Token Attacks

A practical guide to OAuth 2.0 and OIDC attacks - redirect_uri abuse, state/CSRF, PKCE, and token leakage - with blue-team defenses.