Ep. 12 โ€“ Timing Attacks & Mobile OAuth Hijack: When Microseconds and Misflows Betray You

Hacked & Secured: Pentest Exploits & Mitigations

Hacked & Secured: Pentest Exploits & Mitigations
Ep. 12 โ€“ Timing Attacks & Mobile OAuth Hijack: When Microseconds and Misflows Betray You
Aug 29, 2025 Season 1 Episode 12
Amin Malekpour

A few microseconds. One silent browser session. Thatโ€™s all it took for attackers to break into systems without tripping a single alert.

In this episode of Hacked & Secured: Pentest Exploits & Mitigations, we explore two subtle but devastating flaws:

๐Ÿ”น Timing Attacks for Token Leaks โ€“ By measuring microsecond delays, attackers were able to recover secrets, without seeing them in responses.

๐Ÿ”น OAuth Hijack via Mobile App Flows โ€“ A crafted app abused in-app browser sessions and custom URL schemes to silently steal valid login tokens from users on iOS.

These arenโ€™t theoretical bugsโ€”they were found in the wild and affect real apps. If you build or test auth systems, this episode is for you.

Chapters:

00:00 - INTRO

01:11 - FINDING #1 - Timing Leaks That Speak Volumes

06:56 - FINDING #2 - Hijacking Mobile OAuth with One Silent Redirect

13:06 - OUTRO

Want your pentest discovery featured? Submit your creative findings through the Google Form in the episode description, and we might showcase your finding in an upcoming episode!

๐ŸŒ Follow & Connect โ†’ LinkedIn, YouTube, Twitter, Instagram
๐Ÿ“ฉ Submit Your Pentest Findings โ†’ https://forms.gle/7pPwjdaWnGYpQcA6A
๐Ÿ“ง Feedback? Email Us โ†’ podcast@quailu.com.au 
๐Ÿ”— Podcast Website โ†’ Website Link