Open Redirects
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Most web-applications make use of redirects. If your site forwards to URLs supplied in a query string, you could be enabling phishing attacks.
- Prevalence
- Common
- Exploitability
- Easy
- Impact
- Worrying
What is an open redirect?
An open redirect is a redirection vulnerability in which an application forwards users to a URL taken from untrusted input, such as a query string parameter, without validating it. Attackers use it in phishing attacks, crafting links that start on your trusted domain but deliver the victim to a malicious site that steals credentials or installs malware.
What you'll learn
- How an unvalidated redirect parameter turns your domain into phishing bait
- Why links that start on a trusted site get past email filters
- How to restrict redirects to URLs on your own site
Where this lesson counts
OWASP Top 10
Users act outside their intended permissions, exposing or modifying data they should never reach. Now includes SSRF.
OWASP has listed unvalidated redirects and forwards under Broken Access Control since 2021.
Learn more about A01This lesson includes
-
Open Redirects lab
Your site redirects users after login to whatever URL is in the next parameter. Follow Mal as he builds a disguised link to your login page, emails it to Vic and gets past the email provider's checks. Vic logs in and lands on Mal's site.
-
How to prevent Open Redirects
The prevention guide covers two approaches:
- Disallow Offsite Redirects
- Check the Referrer When Doing Redirects
-
Open Redirects quiz
Two questions. Passing marks the lesson complete.
Sources
- What is Open Redirect? StackHawk
- What is an Open Redirection Vulnerability and How to Prevent it? Netsparker
- What is an Open Redirect? Invicti
Related lessons
Browse all 45 lessons
Email Spoofing
Email spoofing is the sending of email messages with a forged "from" address.
Host Header Poisoning
It's dangerous to rely on the value supplied in the Host header of an HTTP request.
Reflected XSS
When building a website, you need to be sure you do not accidentally create a channel that allows malicious JavaScript to be bounced off your server.
Server-Side Request Forgery
An attacker can use SSRF vulnerabilities to probe your internal network.