mirror of
https://github.com/danielmiessler/SecLists.git
synced 2025-05-07 11:20:53 -04:00
https://infosecwriteups.com/how-did-i-earned-6000-from-tokens-and-scopes-in-one-day-12f95c6bf8aa?source=rss----7b722bfd1b8d---4&gi=1e1df8e602a6
592 lines
9.1 KiB
Text
592 lines
9.1 KiB
Text
|
|
1c
|
|
aal
|
|
abc
|
|
account-audience
|
|
account_info.read
|
|
account_info.write
|
|
accounts-api
|
|
Active2
|
|
activity
|
|
ad
|
|
address
|
|
address2
|
|
address3
|
|
address_
|
|
AddressBookFields
|
|
admin
|
|
admin-aud
|
|
admin-cli-audience
|
|
admin-template
|
|
admin.analytics:read
|
|
admin.apps:read
|
|
admin.apps:write
|
|
admin.barriers:read
|
|
admin.barriers:write
|
|
admin.directory.customer
|
|
admin.directory.customer.readonly
|
|
admin.directory.device.chromeos
|
|
admin.directory.device.chromeos.readonly
|
|
admin.directory.device.mobile
|
|
admin.directory.device.mobile.action
|
|
admin.directory.device.mobile.readonly
|
|
admin.directory.domain
|
|
admin.directory.domain.readonly
|
|
admin.directory.group
|
|
admin.directory.group.member
|
|
admin.directory.group.member.readonly
|
|
admin.directory.group.readonly
|
|
admin.directory.orgunit
|
|
admin.directory.orgunit.readonly
|
|
admin.directory.resource.calendar
|
|
admin.directory.resource.calendar.readonly
|
|
admin.directory.rolemanagement
|
|
admin.directory.rolemanagement.readonly
|
|
admin.directory.user
|
|
admin.directory.user.alias
|
|
admin.directory.user.alias.readonly
|
|
admin.directory.user.readonly
|
|
admin.directory.user.security
|
|
admin.directory.userschema
|
|
admin.directory.userschema.readonly
|
|
admin.invites:read
|
|
admin.invites:write
|
|
admin.teams:read
|
|
admin.teams:write
|
|
admin.usergroups:read
|
|
admin.usergroups:write
|
|
admin.users:read
|
|
admin.users:write
|
|
admin:gpg_key
|
|
admin:org
|
|
admin:org_hook
|
|
admin:public_key
|
|
admin:repo_hook
|
|
adminapi
|
|
administrador
|
|
advancedssoadmin-admin
|
|
agroups
|
|
aks
|
|
AlcanceEmpleate
|
|
algoras-app-scope
|
|
all
|
|
Allgemeines_Template
|
|
AllUserAttributes
|
|
analytics
|
|
analytics/query/data
|
|
analytics/query/metadata
|
|
ape-roles
|
|
api
|
|
api1
|
|
api:read
|
|
apicallers
|
|
apm
|
|
app_version
|
|
application
|
|
ArgoCD
|
|
Atributi-forms
|
|
attribute1
|
|
attributes
|
|
attributes_Json
|
|
aud
|
|
aud-mapper-scope
|
|
audience
|
|
auth-test-stagging-admin
|
|
authorizations:read
|
|
avl
|
|
avl_id
|
|
base
|
|
brightfit_user_id
|
|
broker-audience
|
|
browsepy
|
|
ca-assessments
|
|
ca-config
|
|
ca-profiles
|
|
calls:read
|
|
calls:write
|
|
camunda-rest-api
|
|
capital2-audience
|
|
CARE-audience
|
|
CARE-service-audience
|
|
cdsi
|
|
certificate
|
|
changeUser
|
|
channels:history
|
|
channels:join
|
|
channels:manage
|
|
channels:read
|
|
channels:write
|
|
chat:write
|
|
chat:write:bot
|
|
chat:write:user
|
|
chatbot
|
|
cherry-lumen
|
|
cila-admin
|
|
claims_openid
|
|
client-role
|
|
client-roles
|
|
client-scope
|
|
client_orchestrator_id
|
|
ClientConfig
|
|
clientmapper
|
|
cloud-platform
|
|
coffeeandit
|
|
CoffeeAndITRole
|
|
collection-svc
|
|
company:operations
|
|
company:support
|
|
company_ids
|
|
connections:write
|
|
contacts.read
|
|
contacts.write
|
|
contentApi
|
|
conversations.connect:manage
|
|
conversations.connect:write
|
|
cpsadmins-admin
|
|
cpsdevelopers-admin
|
|
cpsotherusers-admin
|
|
csm_region
|
|
cuit
|
|
custom_scope
|
|
customer-control.itential.io
|
|
data-gateway-api
|
|
default
|
|
delete-after-date1619708000534-admin
|
|
delete:packages
|
|
delete_repo
|
|
dev-bearer-client
|
|
device:read
|
|
device:write
|
|
devstorage.full_control
|
|
devstorage.read_only
|
|
devstorage.read_write
|
|
dexcom
|
|
displayname
|
|
dnd:read
|
|
dnd:write
|
|
dnd:write:user
|
|
dns-admin-manager
|
|
doc-test
|
|
dossiers:checkKBO
|
|
dtc:read
|
|
dtc:write
|
|
email
|
|
email2
|
|
email3
|
|
email_
|
|
emoji:read
|
|
employee
|
|
erp_api.hayleyhub.uk.all
|
|
erp_credentials
|
|
esp-pact-client-scope
|
|
etherpad
|
|
event:edit
|
|
eventival
|
|
events.read
|
|
evotor
|
|
family_name
|
|
farhang-keycloak-proxy
|
|
fat-jwt-data
|
|
federated
|
|
fhirUser
|
|
file_requests.read
|
|
file_requests.write
|
|
files.content.read
|
|
files.content.write
|
|
files.metadata.read
|
|
files.metadata.write
|
|
files.permanent_delete
|
|
files.team_metadata.write
|
|
files:read
|
|
files:write
|
|
files:write:user
|
|
firstname
|
|
fiware-scope
|
|
fixture-advancedssoadmin-admin
|
|
fixture-disabl-with-authorit-admin
|
|
fixture-disabled-org-admin
|
|
fixture-enabl-with-authority-admin
|
|
fixture-enabled-org-admin
|
|
fixture-existing-organization-admin
|
|
fixture-existing-organization2-admin
|
|
fixture-org1-multi-org-user-admin
|
|
fixture-org2-multi-org-user-admin
|
|
foobar
|
|
forms-tenants
|
|
fraas_client_scope
|
|
fred_master_test_client_scope
|
|
fullname
|
|
gcp
|
|
gcp-partner
|
|
gist
|
|
Gitlab
|
|
given_name
|
|
good-role
|
|
good-service
|
|
google
|
|
grafana
|
|
group
|
|
group-scope
|
|
Groups
|
|
groups
|
|
groups.read
|
|
groups.write
|
|
groups:history
|
|
groups:read
|
|
groups:write
|
|
groups_as_list
|
|
harbor
|
|
haukesprog
|
|
heartrate
|
|
hello-service
|
|
home-jenkins
|
|
home-users
|
|
https://id.fedoraproject.org/scope/groups
|
|
https://mbsa.cclinux.org/oidc/mbs-submit-build
|
|
hydrosense
|
|
iam
|
|
iam-open-broker-api-access
|
|
id
|
|
id_docs
|
|
identity.basic
|
|
identity.basic:user
|
|
identity:read:user
|
|
identity:read:user:user
|
|
igneel
|
|
im:history
|
|
im:read
|
|
im:write
|
|
INBO_Java_Application
|
|
indicagro-service
|
|
ionic-demo
|
|
Jaeger-cicd-scope
|
|
jaeger-dev-scope
|
|
Jenkins-azure
|
|
jhipster
|
|
Jira
|
|
Jitsi
|
|
jwt_client
|
|
k8s_dev_resources
|
|
k8s_dev_scope
|
|
kanboard
|
|
karma
|
|
keenetic_rmm_beta
|
|
kernos
|
|
kheops
|
|
kibana
|
|
klienten
|
|
knowledge-center-admin-portal-audience
|
|
knowledge-center-apikey-provider-audience
|
|
knowledge-center-audience
|
|
knowledge-center-service-audience
|
|
lagrama-read
|
|
language
|
|
lastname
|
|
launch
|
|
launch/patient
|
|
ldap_dn
|
|
Linking_accounts
|
|
links:write
|
|
location
|
|
login
|
|
manage-realm
|
|
manageUsers
|
|
marketScope
|
|
masdata.company.create
|
|
masdata.company.delete
|
|
masdata.company.list
|
|
masdata.company.read
|
|
masdata.company.update
|
|
master-api
|
|
Mattermost
|
|
md-buyline
|
|
medapproved-audience
|
|
mediawiki
|
|
members.delete
|
|
members.read
|
|
members.write
|
|
membership
|
|
merchantAccesses
|
|
mesh7-gk-scope
|
|
microprofile-jwt
|
|
microprofile-jwt_
|
|
microsoft_role
|
|
midas-api/.default
|
|
minio-policy
|
|
mkd-demo-admin
|
|
ml_app
|
|
mobisis-students
|
|
mobisis-teachers
|
|
moderation
|
|
mpim:history
|
|
mpim:read
|
|
mpim:write
|
|
mt2-audience
|
|
mt2-ios-audience
|
|
mt2-web-ui-audience
|
|
myvalueid
|
|
name
|
|
nbf
|
|
nbrownMapperService
|
|
new_client_scope
|
|
next-profile
|
|
Nextcloud
|
|
normalized-openid
|
|
notification
|
|
notifications
|
|
Notificator
|
|
nutrition
|
|
OAuth Scope
|
|
oauth2_proxy_token
|
|
oauth_client
|
|
odoo
|
|
office_data
|
|
offices
|
|
offline_access
|
|
offline_access2
|
|
offline_access3
|
|
offline_access_
|
|
ois
|
|
ois_oncore_viewer
|
|
oneadvanced-admin
|
|
openid
|
|
openid_client
|
|
openid_connect
|
|
OpenID_PV_Basic_User_Info
|
|
ops-services
|
|
orchestrator.ops.all
|
|
org-tmp1-admin
|
|
org-tmp2-admin
|
|
org-tmp3-admin
|
|
org-tmp4-admin
|
|
org-tmp5-admin
|
|
organization
|
|
organizational_information
|
|
organizations
|
|
ovirt-app-admin
|
|
ovirt-app-api
|
|
ovirt-ext=auth:sequence-priority=~
|
|
panda
|
|
partner-api-client
|
|
patient-api-client
|
|
patient/*.*
|
|
patient/*.read
|
|
patient/AllergyIntolerance.read
|
|
patient/CarePlan.read
|
|
patient/CareTeam.read
|
|
patient/Condition.read
|
|
patient/Device.read
|
|
patient/DiagnosticReport.read
|
|
patient/DocumentReference.read
|
|
patient/Encounter.read
|
|
patient/Goal.read
|
|
patient/Immunization.read
|
|
patient/Location.read
|
|
patient/Medication.read
|
|
patient/MedicationRequest.read
|
|
patient/Observation.read
|
|
patient/Organization.read
|
|
patient/Patient.*
|
|
patient/Patient.read
|
|
patient/Practitioner.read
|
|
patient/PractitionerRole.read
|
|
patient/Procedure.read
|
|
patient/Provenance.read
|
|
patient/RelatedPerson.read
|
|
patientId
|
|
paulmowat-admin
|
|
performance001-admin
|
|
performance002-admin
|
|
performance003-admin
|
|
performance004-admin
|
|
performance005-admin
|
|
performance006-admin
|
|
performance007-admin
|
|
performance008-admin
|
|
performance009-admin
|
|
performance010-admin
|
|
permission
|
|
phone
|
|
phone2
|
|
phone3
|
|
phone_
|
|
pins:read
|
|
pins:write
|
|
PITMA
|
|
platform-cps-admin
|
|
platform_audience
|
|
pnum
|
|
portaal
|
|
portal-sachen
|
|
postgraphile
|
|
profile
|
|
profile2
|
|
profile3
|
|
profile_
|
|
project:edit
|
|
project:read
|
|
project:view
|
|
provider-portal-prod-audience
|
|
PSCUser
|
|
public_repo
|
|
rapier
|
|
reactions:read
|
|
reactions:write
|
|
read
|
|
read:discussion
|
|
read:org
|
|
read:packages
|
|
read:public_key
|
|
read:repo_hook
|
|
read:user
|
|
realm-management
|
|
realm-management-audience
|
|
registrar
|
|
registry
|
|
reminders:read
|
|
reminders:read:user
|
|
reminders:write
|
|
reminders:write:user
|
|
remote_files:read
|
|
remote_files:share
|
|
remote_files:write
|
|
repo
|
|
repo:invite
|
|
repo:status
|
|
repo_deployment
|
|
resource_access.cumulocity.roles
|
|
restheart
|
|
rm_client_scope
|
|
role
|
|
ROLE_ADMIN
|
|
role_list
|
|
roles
|
|
roles_
|
|
roles_id_token
|
|
sanlam
|
|
sap-adapter-admin
|
|
schedule_zoom_meetings
|
|
school-person-info
|
|
scope_minio_mapper
|
|
ScopeLevel_JWTauthentication_REST_ExternalAuthServer
|
|
search:read
|
|
Security
|
|
security-admin-console-audience
|
|
security_events
|
|
service
|
|
service-template
|
|
service.management
|
|
services
|
|
sessions.list
|
|
sessions.modify
|
|
settings
|
|
sharing.read
|
|
sharing.write
|
|
sjpscope
|
|
skb_scope
|
|
sleep
|
|
slim-jwt-pv-info
|
|
smart_city_profile
|
|
social
|
|
Sonarqube
|
|
source.full_control
|
|
source.read_only
|
|
source.read_write
|
|
stars:read
|
|
stars:write
|
|
stone_code
|
|
Strapi
|
|
students
|
|
studioRGId
|
|
subscription
|
|
sudoers
|
|
taka-org-ze-hej-c1-o1-admin
|
|
taka-org-ze-hej-c1-o2-admin
|
|
teachers
|
|
team:read
|
|
team_data.member
|
|
team_data.team_space
|
|
team_info.read
|
|
test
|
|
test-admin
|
|
test-resources2-users-admin
|
|
test-resources2-users-read
|
|
test-resources2-users-service-account
|
|
test-resources2-users-write
|
|
test-service
|
|
test-service-account-scope
|
|
test-template
|
|
test-two-admin
|
|
test123
|
|
test2-admin
|
|
test4-admin
|
|
test_scope
|
|
testcrmscope
|
|
testfive-admin
|
|
testscope
|
|
testseven-admin
|
|
testsix-admin
|
|
testtimeout10-admin
|
|
testtimeout11-admin
|
|
testtimeout13-admin
|
|
testtimeout5-admin
|
|
testtimeout6-admin
|
|
testtimeout7-admin
|
|
testtimeout8-admin
|
|
testtimeout9-admin
|
|
ti-api
|
|
ti-api-access
|
|
ti-api-admin-access
|
|
tm-analytics-api-audience
|
|
tm-analytics-api-service-audience
|
|
tmh-gateway-audience
|
|
tokens.basic
|
|
transport-scope
|
|
tsr.admin
|
|
tsr.write
|
|
ttyd
|
|
uhc
|
|
uid
|
|
uma_protection
|
|
urn:kafka:cluster:kafka-cluster:cluster_action
|
|
user
|
|
user.read
|
|
user/*.*
|
|
user:email
|
|
user:follow
|
|
usergroups:read
|
|
usergroups:write
|
|
userinfo.email
|
|
UserManagement
|
|
Username
|
|
username
|
|
users.profile:read
|
|
users.profile:write
|
|
users.profile:write:user
|
|
users:read
|
|
users:read.email
|
|
users:write
|
|
vehicle:read
|
|
vehicle:write
|
|
vero-permissions
|
|
VNR
|
|
warehouse_id
|
|
web-origins
|
|
web-origins_
|
|
web-roles_(db-stage)
|
|
webhook
|
|
webmasters
|
|
weight
|
|
whoami
|
|
wiki-devops
|
|
wordpress
|
|
workflow.steps:execute
|
|
WPGroups
|
|
write:discussion
|
|
write:gpg_key
|
|
write:org
|
|
write:packages
|
|
write:public_key
|
|
write:repo_hook
|
|
wx_open_id
|
|
xwiki_groups
|