ناضي كناظي Profile picture
ان ينصركم الله فلا غالب لكم
Sep 27, 2023 6 tweets 2 min read
MSRC bug 🐛🐛
A month ago I noticed people talking about devtunnels
I was so fascinated by the "new ngrok", after poking around for some time. I stumbled on this redirection which send the AAD token for oauth flow 1/nlearn.microsoft.com/en-us/azure/de… the url looked like this global.rel.tunnels.api.visualstudio[.]com/auth/postback?pb=url&scheme=aad where url is your private devtunnel url, the issue was your token can be sent to any devtunnel url, basically an open redirect to anything.uks1.devtunnels[.]ms 2/n