Interested in going full-time bug bounty? Check out our blueprint!

Stealing oAuth tokens with Frans Rosen!

Here's an interesting one folks!

Frans discovered state validation was happening before you acquire the code so you can get the victim to use your state instead.