<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>OAuth | He (Shawn) Shuang's Personal Site</title><link>https://8759s.github.io/tags/oauth/</link><atom:link href="https://8759s.github.io/tags/oauth/index.xml" rel="self" type="application/rss+xml"/><description>OAuth</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Fri, 24 Jul 2026 00:00:00 +0000</lastBuildDate><image><url>https://8759s.github.io/media/icon_hu_1035bcf07d2ae8d9.png</url><title>OAuth</title><link>https://8759s.github.io/tags/oauth/</link></image><item><title>Device Code Phishing Evasion Techniques</title><link>https://8759s.github.io/news/device-code-phishing-evasion-techniques/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>https://8759s.github.io/news/device-code-phishing-evasion-techniques/</guid><description>&lt;p>We observed device-code phishing campaigns using four complementary evasion techniques. CAPTCHA gates block basic URL scanners while mimicking legitimate Microsoft security checks, and multi-step flows route victims through trusted SaaS platforms before revealing the phishing page.&lt;/p>
&lt;p>Other campaigns decrypt phishing HTML inside the browser and deliver it through a session-unique blob URL that blocklists cannot retrieve. The pages also disrupt content detection with Cyrillic lookalike characters, zero-width spaces and randomized strings embedded in &lt;code>&amp;lt;bdi&amp;gt;&lt;/code> elements, while remaining visually convincing to victims.&lt;/p>
&lt;p>
&lt;/p></description></item><item><title>Device Code-based OAuth Phishing</title><link>https://8759s.github.io/news/device-code-based-oauth-phishing/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://8759s.github.io/news/device-code-based-oauth-phishing/</guid><description>&lt;p>This active campaign abuses Microsoft&amp;rsquo;s legitimate device-code OAuth flow to capture application tokens instead of passwords. Victims interact with a real Microsoft sign-in page while the attacker&amp;rsquo;s infrastructure obtains the resulting token in the background.&lt;/p>
&lt;p>The phishing pages combine trusted authentication flows with obfuscated payloads, developer-tool detection and debugger traps. A captured OAuth token can provide application-level access to email, files and identity data without exposing the victim&amp;rsquo;s password.&lt;/p>
&lt;p>
&lt;/p></description></item></channel></rss>