Web App Pentest Checklist
search
⌘Ctrlk
Web App Pentest Checklist
  • Recon
  • Registration Feature Testing
  • Email Verification Bypass
  • Forgot Password
  • Forgot Password Testing
  • Rate Limit Bypass
  • Account Takeover
  • API Authentication
  • Session Management Testing
  • Authentication Testing
    • Test Oauth login functionality
      • OAuth Roles
      • Code Flaws
      • Redirect_uri Flaws
      • State Flaws
      • Misc
    • Test 2FA Misconfiguration
    • OTP Bypass
  • My Account (Post Login) Testing
  • Contact Form Testing
  • Product Purchase Testing
  • Open Redirection Testing
  • Host Header Injection
  • SQL Injection Testing
  • Cross-Site Scripting Testing
  • CSRF Testing
  • SSO Vulnerabilities
  • XML Injection Testing
  • Cross-origin resource sharing (CORS)
  • Server-side request forgery (SSRF)
  • CAPTCHA Testing
  • File Upload Testing
  • WebSockets Testing
  • GraphQL Vulnerabilities Testing
  • Denial of Service
  • RCE
  • Other Test Cases (All Categories)
  • Extra Reference
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Authentication Testing

Test Oauth login functionality

OAuth Roleschevron-rightCode Flawschevron-rightRedirect_uri Flawschevron-rightState Flawschevron-rightMiscchevron-right
PreviousAuthentication Testingchevron-leftNextOAuth Roleschevron-right