SKILL: Open Redirect — Expert Attack Playbook
AI LOAD INSTRUCTION: Open redirect techniques. Covers parameter-based redirects, JavaScript sinks, filter bypass, and chaining with phishing, CSRF Referer bypass, OAuth token theft, and SSRF. Often underrated but critical for phishing and as a building block in multi-step exploit chains.
1. CORE CONCEPT
Open redirect occurs when an application redirects users to a URL derived from user input without validation. The trusted domain acts as a "launchpad" for phishing or token theft.
2. FINDING REDIRECT PARAMETERS
Common Parameter Names
Server-Side Sinks
Client-Side (JavaScript) Sinks
3. FILTER BYPASS TECHNIQUES
4. EXPLOITATION CHAINS
Phishing Amplification
Attacker sends: https://bigbank.com/redirect?url=https://bigbank-login.evil.com
Victim sees bigbank.com → clicks → enters credentials on clone site.
OAuth Token Theft
If OAuth redirect_uri allows open redirect on the authorized domain:
CSRF Referer Bypass
Some CSRF protections check Referer header contains trusted domain:
SSRF via Redirect
When server follows redirects:
5. TESTING CHECKLIST
6. TABNABBING (REVERSE TABNABBING)
Concept
When a link opens a new tab with target="_blank" WITHOUT rel="noopener":
- The new page can access
window.opener - It can redirect the ORIGINAL page:
window.opener.location = "https://phishing.com/login" - User returns to "original" tab → sees fake login page → enters credentials
Detection
Exploitation
Where to Look
- User-generated content with links (forums, comments, profiles)
target="_blank"links to external domains- PDF viewers, document previews opening in new tabs
7. OPEN REDIRECT → OAUTH TOKEN THEFT (DETAILED CHAINS)
7.1 OAuth Implicit Flow
In the implicit flow, the access token is returned in the URL fragment (#access_token=...). If redirect_uri allows an open redirect on the authorized domain:
7.2 Authorization Code Flow
The authorization code is sent as a query parameter. If the redirect chain preserves query parameters:
7.3 OIDC id_token Fragment Leak
7.4 redirect_uri validation bypass patterns
8. OPEN REDIRECT → SSRF CHAIN
Server-side redirect following
When a server-side component follows HTTP redirects (e.g., URL preview, link unfurler, webhook, image fetcher):
Multi-hop redirect for filter bypass
DNS rebinding variant
Scope escalation via redirect protocols
Not all HTTP clients follow cross-protocol redirects, but curl (default) and some libraries do.
9. URL PARSER CONFUSION FOR REDIRECT BYPASS
When a redirect validation function parses the URL differently from the browser or server that ultimately processes it:


