Logical Exploits Of Arbitrary URL Jump

By XiaoXin
A Bit Randomly

Main Contents

Logical Exploits Of Arbitrary URL Jump

The url redirection vulnerability is also called exploit redirection vulnerability, which can redirect the user to the page constructed by the attacker himself. Simply put, it can jump to any specified url. Generally appear in the verification jump, sso login and other positions.

The server does not check and control the incoming redirect url variable, which may lead to the malicious construction of any malicious address, and induce users to jump to malicious websites.

  • Phishing
  • Cooperate with CSRF to operate dangerous requests
  • Cooperate with XSS to execute JS to steal cookies
  • Mating browser vulnerability (CVE-2018-8174)

You can jump to the corresponding page after replacing the url parameter, but some websites may restrict the url jump, you can try to bypass bypass.

