15–25 min Updated

Open Redirects

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Most web-applications make use of redirects. If your site forwards to URLs supplied in a query string, you could be enabling phishing attacks.

Prevalence
Common
Exploitability
Easy
Impact
Worrying

What is an open redirect?

An open redirect is a redirection vulnerability in which an application forwards users to a URL taken from untrusted input, such as a query string parameter, without validating it. Attackers use it in phishing attacks, crafting links that start on your trusted domain but deliver the victim to a malicious site that steals credentials or installs malware.

What you'll learn

  • How an unvalidated redirect parameter turns your domain into phishing bait
  • Why links that start on a trusted site get past email filters
  • How to restrict redirects to URLs on your own site

Where this lesson counts

OWASP Top 10

  • Open Redirects lab

    Your site redirects users after login to whatever URL is in the next parameter. Follow Mal as he builds a disguised link to your login page, emails it to Vic and gets past the email provider's checks. Vic logs in and lands on Mal's site.

  • How to prevent Open Redirects

    The prevention guide covers two approaches:

    • Disallow Offsite Redirects
    • Check the Referrer When Doing Redirects
  • Open Redirects quiz

    Two questions. Passing marks the lesson complete.

Sources

  • Email Spoofing

    Email spoofing is the sending of email messages with a forged "from" address.

  • Host Header Poisoning

    It's dangerous to rely on the value supplied in the Host header of an HTTP request.

  • Reflected XSS

    When building a website, you need to be sure you do not accidentally create a channel that allows malicious JavaScript to be bounced off your server.

  • Server-Side Request Forgery

    An attacker can use SSRF vulnerabilities to probe your internal network.