Remove B2C Remove Data collection Remove Penetration Testing
article thumbnail

SPA is for Single-Page Abuse! – Using Single-Page Application Tokens to Enumerate Azure

Security Boulevard

Gather403 Errors = Partial Collection Figure 9 Gather with HTTP 403Errors 7. 5000 Figure 10 Partial Data Collection Office 365 ExampleFull Collection with SharePoint Token Inspect Figure 11 Web Inspection and Network Filtering 2. Authenticate with ROADRecon Figure 8 Successful Authentication with RefreshToken 6.