open redirect
Redirect to attacker domains by exploiting incomplete validation of the redirect parameter.
Quick answer
What is open redirect?
Redirect to attacker domains by exploiting incomplete validation of the redirect parameter.
Articles
3
Beginner
0
Intermediate
2
Advanced
1
Intermediate level
2OAuth attacks — state CSRF, redirect_uri bypass, token reuse, token IDOR
Vulnerabilities in OAuth 2.0 flows: missing state parameter, redirect_uri loose validation, cross-app token reuse, IDOR in token refresh endpoints.
Open Redirect via Backslash Bypass in the OAuth Login's redirect_url
The client-side validator checks //, : and /. The backslash slips through. Browsers normalize it to a slash and the victim ends up on evil.tld with an active session cookie.
Advanced level
1Practice open redirect with real labs
Apply the techniques in safe environments based on real bug bounty reports.
- hunters training
- 711
- labs from real reports
- 55
- completions
- 1,205
- in bounties practiced
- $213,970
hunters training
labs from real reports
completions
in bounties practiced
Stop reading about bugs and start hunting them
Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.
No card · free Academy · cancel anytime