Open Redirect to XSS to Account Takeover to $$$$

1 month ago 32
BOOK THIS SPACE FOR AD
ARTICLE AD

Raunak Gupta Aka Biscuit

OSINT Team

Free Article Link: Here!!!

I was casually poking around a web app, when I spot an open redirect vulnerability just chilling like it’s no big deal. You know the drill, user clicks a link, and boom, they get redirected to whatever URL you throw in. Easy peasy. But wait, why stop at an open redirect when you can take things to the next level? he he he

Playing around with OpenRedirect Parameter

I figured, “Hey, what if I could sneak some JavaScript into this redirect?”, and bam we’ve Xss pop up, and just like that, I’m able to steal cookies and hijack sessions. XSS isn’t just for showing funny alerts, friends. It’s for serious business , like hijacking accounts! 😏

Reference Report:

Bounty!!! Bounty!!! Bounty!!!

Read Entire Article