Open Redirect

Burp'ten tespiti:

Target > Sitemap'e gel. Filtreleye tıkla. Sadece 300 kodluluları göster. Çünkü Redirect zaten genelde 300 statüs kodunda olur.

Google dorking

inurl:redirectUrl=http site:target.com

Bulunabilecek Fonksiyonlar

  • Login, Logout, Register & Password reset pages

  • Change site language

  • Links in emails

HTTP Redirection Status Code - 3xx

Using "//" & "////" to bypass "http" blacklisted keyword

Using "https:" to bypass "//" blacklisted keyword

Using "//" to bypass "//" blacklisted keyword (Browsers see // as //)

Using "%E3%80%82" to bypass "." blacklisted character

Using null byte "%00" to bypass blacklist filter

Using parameter pollution

Using "@" character, browser will redirect to anything after the "@"

Creating folder as their domain

Using "?" characted, browser will translate it to "/?"

Host/Split Unicode Normalization

XSS from Open URL - If it's in a JS variable

XSS from data:// wrapper

XSS from javascript:// wrapper

Open Redirect uploading svg files

Tespit Edebilecek Parametreler:

Tool:

Payload Oluşturmaya Yarayan Tool:

Ref:

Last updated