Open Redirect

Common Bypasses

#Using Base64 - urlencode(base64(//google.com\@whitelisteddomain.tld))
Ly9nb29nbGUuY29tXEB3aGl0ZWxpc3RlZGRvbWFpbi50bGQ%3D

Common Injection Points

Add your payload at the end of the line.

/
?next=
?url=
?target=
?rurl=
?dest=
?destination=
?redir=
?redirect_uri=
?redirect_url=
?redirect=
/redirect/
/cgi-bin/redirect.cgi?
/out/
/out?
?view=
/login?to=
?image_url=
?go=
?return=
?returnTo=
?return_to=
?checkout_url=
?continue=
?return_path=

Payloads

Change whitelisteddomain with an specific white listed domain of your case. Ex: www.web.com

Last updated

Was this helpful?