Automating the enumeration of missing reply URLs in Azure multitenant apps
ID: 6c2bab45-54da-5b19-911a-9e97151758e3
STIX ID: report--6c2bab45-54da-5b19-911a-9e97151758e3
Feed Name: FalconForce
This post presents reply-url-brute, a Python tool and methodology to automatically enumerate missing reply URLs in Azure multitenant applications by probing OAuth authorize/token flows, undocumented Graph endpoints, scope brute-forcing, and using the ESTSAUTHPERSISTENT cookie; it identifies unregistered reply URLs that, if an attacker can register the domain or obtain a session cookie, may allow issuing tokens, user impersonation, or full tenant takeover. Microsoft was notified and acknowledged the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
