Hackfest - Level UP

OAuth Abuse & Exploitation: Implicit Trust is the New Attack Surface
Langue: English

As a Cybersecurity Solution Consultant at Palo Alto Networks and ethical hacking professor at the University of Sherbrooke, Clément Cruchet is backed by deep experience in offensive security, network security, and incident response. This provides a holistic view of the full attack lifecycle. In this talk, he applies this expertise to cloud identity platforms, bridging the gap between theoretical OAuth RFC protocols and real-world exploitation, to show how attackers weaponize these implementations and how defenders can secure them.


OAuth has become the backbone of identity delegation in modern SaaS and cloud environments - and threat actors are aggressively targeting it. Because it operates outside traditional network perimeters and often bypasses standard security controls, OAuth has emerged as a highly attractive target for attackers seeking stealth access, persistent, MFA-resistant access to enterprise environments.

This talk takes an offensive practitioner's perspective on how OAuth 2.0 and its implementations across multiple platforms and third-party SaaS are being actively weaponized. We will start with a foundational look at the (multiples) OAuth RFC, contrasting the core mechanisms that make the protocol secure with the poor implementation choices and misconfigurations that render it vulnerable in the real world. We'll also examine the latest attack trends capitalizing on these gaps.

From there, we will walk through the full attack lifecycle abusing OAuth specific implementation and real life example from initial access to lateral movement and chain OAuth token theft with refresh token replay to maintain long-lived persistence and stealthy access that survives password resets.

The session includes pre-recorded demo clips showing real exploitation scenarios including device code phishing, fake application abusing OAuth, token extraction from compromised endpoints, and post-exploitation abuses.

The speaker’s profile picture
Clément Cruchet

As a Cybersecurity Solution Consultant at Palo Alto Networks and ethical hacking professor at the University of Sherbrooke, Clément Cruchet is backed by experience in offensive security, network security, and incident response. This provides a holistic view of the full attack lifecycle. In this talk, he applies this expertise to cloud identity platforms to show how attackers exploit OAuth implementations for persistent access.