Uploaded June 2026 | Updated September 2026, 6 hours ago
Auth bugs pay the most in bug bounty, and most hunters skip them because they never actually learned how auth works. This video fixes that. I break down sessions, JWTs, OAuth 2.0, the Authorisation Code Flow, PKCE, and OpenID Connect from a hacker's perspective. Why every protection exists, what it defends, and the exact bug that shows up when it's missing.
π― Get My Full Caido For Hackers Course: hhub.io/AMRCAIDO
π‘ Support AmrSec on Patreon:
patreon.com/AmrSec
π₯ Join Our Community:
Discord: discord.gg/nxHKyJTy3h
π Resources
Video Article: amrelsagaei.com/auth-for-hackers
β Become a Channel Member:
youtube.com/@AmrSecOfficial/join
β οΈ Disclaimer
This channel is for educational purposes only. The goal is to teach cybersecurity, ethical hacking, and red team/blue team skills through real tools, techniques, and experience. Always hack ethically. π«‘
π Timestamps
00:00 β Introduction
01:37 β The Two Questions
05:27 β Passwords and Sessions
16:41 β JWTs
28:02 β OAuth 2.0 From Zero
38:34 β The Authorisation Code Flow
51:20 β PKCE
1:03:03 β The Other OAuth Flows
1:14:51 β OpenID Connect
1:27:29 β The Security Design Table
1:35:06 β Conclusion
Follow AmrSec
LinkedIn: linkedin.com/in/amrelsagaei
Twitter/X: twitter.com/amrelsagaei
Instagram: instagram.com/amrelsagaei
#BugBounty #WebSecurity #OAuth #JWT #AmrSec
Auth bugs pay the most in bug bounty, and most hunters skip them because they never actually learned how auth works. This video fixes that. I break down sessions, JWTs, OAuth 2.0, the Authorisation Code Flow, PKCE, and OpenID Connect from a hacker's perspective. Why every protection exists, what it defends, and the exact bug that shows up when it's missing.
π― Get My Full Caido For Hackers Course: hhub.io/AMRCAIDO
π‘ Support AmrSec on Patreon:
patreon.com/AmrSec
π₯ Join Our Community:
Discord: discord.gg/nxHKyJTy3h
π Resources
Video Article: amrelsagaei.com/auth-for-hackers
β Become a Channel Member:
youtube.com/@AmrSecOfficial/join
β οΈ Disclaimer
This channel is for educational purposes only. The goal is to teach cybersecurity, ethical hacking, and red team/blue team skills through real tools, techniques, and experience. Always hack ethically. π«‘
π Timestamps
00:00 β Introduction
01:37 β The Two Questions
05:27 β Passwords and Sessions
16:41 β JWTs
28:02 β OAuth 2.0 From Zero
38:34 β The Authorisation Code Flow
51:20 β PKCE
1:03:03 β The Other OAuth Flows
1:14:51 β OpenID Connect
1:27:29 β The Security Design Table
1:35:06 β Conclusion
Follow AmrSec
LinkedIn: linkedin.com/in/amrelsagaei
Twitter/X: twitter.com/amrelsagaei
Instagram: instagram.com/amrelsagaei
#BugBounty #WebSecurity #OAuth #JWT #AmrSec








