Detected whether the target was protected by Google's Identity-Aware Proxy (IAP). IAP provided application-level access control for services running on Google Cloud. When IAP intercepted an unauthenticated request, it set the X-Goog-Iap-Generated-Response header and redirected the request to Google OAuth. The second request followed the redirects to the consent screen and extracted the OAuth client_id, application owner, contact email, and display name.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view