MSRC bug 🐛🐛
A month ago I noticed people talking about devtunnels
I was so fascinated by the "new ngrok", after poking around for some time. I stumbled on this redirection which send the AAD token for oauth flow 1/nlearn.microsoft.com/en-us/azure/de…
the url looked like this global.rel.tunnels.api.visualstudio[.]com/auth/postback?pb=url&scheme=aad where url is your private devtunnel url, the issue was your token can be sent to any devtunnel url, basically an open redirect to anything.uks1.devtunnels[.]ms 2/n