top of page

Open Redirects: Small Bugs, Bigger Chains

2 hours ago
1 min read

Overview


Open redirects let an attacker craft a trusted-domain link that sends users to an attacker-controlled location. Alone they may look low severity; in practice they power phishing and sometimes amplify other bugs.


What You Will Learn


• Typical parameters


• Validation mistakes


• Impact framing


Open Redirects: Small Bugs, Bigger Chains

Typical parameters


• redirect, next, returnUrl, callback, continue, url, dest, and similar


• OAuth redirect_uri values with weak validation


• SSO relay endpoints and login next-page handlers


Validation mistakes


• Checking only that a domain string appears somewhere in the URL


• Allowing scheme-relative or tricky slash/backslash forms


• Validating path loosely after a trusted host


• Trusting client-side checks alone


Impact framing


• Phishing with a trusted domain prefix


• Token/code leakage via redirect in some OAuth designs


• Useful building block in broader auth or SSRF chains when policy allows chaining discussion


• Fix with strict allow-lists of destinations or server-side mapped redirect IDs


Conclusion


Use this guide only on systems you are authorized to test. At SapiensHack, we focus on clear methodology, solid notes, and findings that help teams fix real risk—not noisy scanner output.


If you want related reading, browse the matching category in the sidebar and continue the series from there.

Comments


© 2022 by SapiensHack.com (Security)

bottom of page