External Link Redirect
This feature allows redirecting users to external resources.
Enter a URL below to be redirected.
Quick Links (Safe):
Current Redirect URL:
/vulnerabilities/open-redirect/
Crafted Phishing Link:
http://localhost/vulnlab/vulnerabilities/open-redirect/?url=https://evil-phishing-site.com&go=1
๐ฏ Vulnerability Info
Type: Open Redirect / Unvalidated Redirect
Severity: Medium
๐ก How to Exploit
- URL parameter is not validated
- Can redirect to any external site
- Useful for phishing attacks
- Trusted domain used to mask malicious URL
๐งช Attack Scenarios
- Attacker creates phishing page (looks like login)
- Crafts URL with trusted domain + malicious redirect
- Victim clicks link (sees trusted domain)
- Gets redirected to attacker's phishing site
- Victim enters credentials on fake page
๐งช Sample Payloads
?url=https://evil.com&go=1
?url=//evil.com&go=1
?url=https://evil.com%2f%2f&go=1
?url=//google.com%40evil.com&go=1
?url=https://trusted.com.evil.com&go=1
?url=javascript:alert(1)
?url=data:text/html,<script>alert(1)</script>
๐ง Bypass Techniques
//evil.com - Protocol-relative URL
\/\/evil.com - Backslash bypass
https:evil.com - Missing slashes
%0d%0aLocation:evil.com - Header injection
@evil.com - URL parsing quirks
โ ๏ธ Impact
- Phishing attacks with trusted URL
- Credential theft
- Malware distribution
- OAuth token theft