{"id":10006,"date":"2021-03-18T12:42:10","date_gmt":"2021-03-18T07:12:10","guid":{"rendered":"https:\/\/www.varutra.com\/?p=10006"},"modified":"2022-12-02T13:07:25","modified_gmt":"2022-12-02T07:37:25","slug":"open-redirect","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/","title":{"rendered":"Open Redirect"},"content":{"rendered":"<h3><strong>What is Open Redirect?<\/strong><\/h3>\n<p>An open redirect is a security flaw in an application or a web page that causes URLs to fail to authenticate properly. The open redirect is a failure in this phase that allows attackers to direct users to malicious websites of third parties.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>When and Where Happens?<\/strong><\/h3>\n<p>Open redirection happens when, via a user-controlled input, a web page is redirected to another URL in another domain. This happens when the program takes user-controlled data to the target of redirection in an unsafe way.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Common dorks for open redirect<\/strong><\/h3>\n<p>Some dorks<\/p>\n<p>\/{payload}<\/p>\n<p>?next=<\/p>\n<p>?url=<\/p>\n<p>?target=<\/p>\n<p>?rurl=<\/p>\n<p>?dest=<\/p>\n<p>?destination=<\/p>\n<p>?redir=<\/p>\n<p>redirect_uri=<\/p>\n<p>?redirect_url=<\/p>\n<p>?redirect=<\/p>\n<p>\/redirect\/<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Finding possible parameters using web archive for open redirection.<\/strong><\/h3>\n<p>Using the below link user can identify maximum parameters that could be tested for open redirection.<\/p>\n<p><a href=\"https:\/\/web.archive.org\/cdx\/search\/cdx?url=*.testphp.vulnweb.com\/*&amp;output=text&amp;fl=original&amp;collapse=urlkey\">https:\/\/web.archive.org\/cdx\/search\/cdx?url=*.testphp.vulnweb.com\/*&amp;output=text&amp;fl=original&amp;collapse=urlkey<\/a><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Automation is possible for checking for open redirect.<\/strong><\/h3>\n<p>Use the following one Liner to test for open redirect.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>gau testphp.vulnweb.com | tee -a archive 1&gt;\/dev\/null &amp;&amp; gf redirect archive | cut -f 3- -d &#8216;:&#8217; | qsreplace &#8220;https:\/\/evil.com&#8221; | httpx -silent -status-code -location<\/strong><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<h3><strong>Below are the GitHub links to the tools.<\/strong><\/h3>\n<ul>\n<li><a href=\"https:\/\/github.com\/lc\/gau\">https:\/\/github.com\/lc\/gau<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/tomnomnom\/gf\">https:\/\/github.com\/tomnomnom\/gf<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/tomnomnom\/qsreplace\">https:\/\/github.com\/tomnomnom\/qsreplace<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/projectdiscovery\/httpx\">https:\/\/github.com\/projectdiscovery\/httpx<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/ffuf\/ffuf\">https:\/\/github.com\/ffuf\/ffuf<\/a><\/li>\n<\/ul>\n<p><strong>\u00a0<\/strong><\/p>\n<h3><strong>SSRF via open redirection.<\/strong><\/h3>\n<p>&nbsp;<\/p>\n<p>This is vulnerable Lab made by Portswigger to test open redirection via ssrf.<\/p>\n<ol>\n<li>Access the lab and capture the request in Burp suite.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-10008 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/check-stock-api-Request.png\" alt=\"Check stock api Request\" width=\"651\" height=\"360\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/check-stock-api-Request.png 651w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/check-stock-api-Request-300x166.png 300w\" sizes=\"(max-width: 651px) 100vw, 651px\" \/><\/p>\n<p style=\"text-align: center\"><strong>Fig 1.1 Check stock api Request<\/strong><\/p>\n<ol start=\"2\">\n<li>Capture check stock request and send the request to repeater.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-10010 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/Next-product-intercept-request.png\" alt=\"Next product intercept request\" width=\"651\" height=\"360\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Next-product-intercept-request.png 651w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Next-product-intercept-request-300x166.png 300w\" sizes=\"(max-width: 651px) 100vw, 651px\" \/><\/p>\n<p style=\"text-align: center\"><strong>Fig-1.2 Next product intercept request<\/strong><\/p>\n<ol start=\"3\">\n<li>Click on next product and send it to the repeater.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-10012 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/Tampering-stock-apiurl.png\" alt=\"Tampering stock apiurl\" width=\"651\" height=\"306\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Tampering-stock-apiurl.png 651w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Tampering-stock-apiurl-300x141.png 300w\" sizes=\"(max-width: 651px) 100vw, 651px\" \/><\/p>\n<p style=\"text-align: center\"><strong>Fig-1.3 Tampering stock apiurl<\/strong><\/p>\n<ol start=\"4\">\n<li>Change the stock api endpoint to <strong>\/product\/nextproduct?path=http:\/\/192.168.0.12:8080\/admin<\/strong><\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-10011 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/Rendering-the-request-in-Burp.png\" alt=\"Rendering the request in Burp\" width=\"651\" height=\"288\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Rendering-the-request-in-Burp.png 651w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Rendering-the-request-in-Burp-300x133.png 300w\" sizes=\"(max-width: 651px) 100vw, 651px\" \/><\/p>\n<p style=\"text-align: center\"><strong>Fig -1.4 Rendering the request in Burp<\/strong><\/p>\n<ol start=\"5\">\n<li>Render the request in the browser. In order to solve the lab, delete Carlos user.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-10007 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/Adding-delete-username-endpoint-in-order-to-delete-carlos-user.png\" alt=\"Adding delete username endpoint in order to delete carlos user\" width=\"651\" height=\"323\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Adding-delete-username-endpoint-in-order-to-delete-carlos-user.png 651w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Adding-delete-username-endpoint-in-order-to-delete-carlos-user-300x149.png 300w\" sizes=\"(max-width: 651px) 100vw, 651px\" \/><\/p>\n<p style=\"text-align: center\"><strong>Fig-1.5 Adding delete username endpoint in order to delete carlos user<\/strong><\/p>\n<ol start=\"6\">\n<li>Add the endpoint to stock api as <strong>delete\/username=carlos<\/strong><\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-10009 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/Lab-Solved-Successfully.png\" alt=\"Lab Solved Successfully\" width=\"651\" height=\"313\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Lab-Solved-Successfully.png 651w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Lab-Solved-Successfully-300x144.png 300w\" sizes=\"(max-width: 651px) 100vw, 651px\" \/><\/p>\n<p style=\"text-align: center\"><strong>Fig-1.6 Lab Solved Successfully<\/strong><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>How Can You Prevent Open Redirection Vulnerabilities?<\/strong><\/h3>\n<p>Not allowing the user to control where your page redirects them to will be the simplest and most efficient way to avoid insecure open Redirects. If you want to redirect the user based on URLs, you can always use an ID that is internally resolved to the respective URL instead of using untrusted input. You can use a redirection page that needs redirection if you want the user to be able to issue redirects.<\/p>\n<p>&nbsp;<\/p>\n<p>Author,<\/p>\n<p><strong>Saketh Reddy Malepu<\/strong><\/p>\n<p>Attack &amp; Pentest Team<\/p>\n<p>Varutra Consulting Pvt. Ltd.<\/p>","protected":false},"excerpt":{"rendered":"<p>What is Open Redirect? An open redirect is a security flaw in an application or a web page that causes URLs to fail to authenticate&#8230;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[280,57,272],"tags":[398],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.6.3 - aioseo.com -->\n\t\t<meta name=\"description\" content=\"What is an Open Redirect security flaw and How to Prevent it? Technical &amp; detailed explanation of the open redirection web or application vulnerability.\" \/>\n\t\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.6.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Open Redirect Security Flaw in Web or Application\" \/>\n\t\t<meta property=\"og:description\" content=\"What is an Open Redirect security flaw and How to Prevent it? Technical &amp; detailed explanation of the open redirection web or application vulnerability.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/check-stock-api-Request.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/check-stock-api-Request.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"651\" \/>\n\t\t<meta property=\"og:image:height\" content=\"360\" \/>\n\t\t<meta property=\"article:section\" content=\"Vulnerability Disclosure\" \/>\n\t\t<meta property=\"article:tag\" content=\"open redirection\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-03-18T07:12:10+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-02T07:37:25+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Open Redirect Security Flaw in Web or Application\" \/>\n\t\t<meta name=\"twitter:description\" content=\"What is an Open Redirect security flaw and How to Prevent it? Technical &amp; detailed explanation of the open redirection web or application vulnerability.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/check-stock-api-Request.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpblogger\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#article\",\"name\":\"Open Redirect Security Flaw in Web or Application\",\"headline\":\"Open Redirect\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/check-stock-api-Request.png\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#articleImage\"},\"datePublished\":\"2021-03-18T12:42:10+05:30\",\"dateModified\":\"2022-12-02T13:07:25+05:30\",\"inLanguage\":\"en-US\",\"commentCount\":2,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#webpage\"},\"articleSection\":\"Viruses &amp; Malware, Vulnerability Disclosure, Web Application Security, Open redirection\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"nextItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#listItem\"},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#listItem\",\"position\":2,\"name\":\"Open Redirect\",\"previousItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\"}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/\",\"name\":\"kalpblogger\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"kalpblogger\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/\",\"name\":\"Open Redirect Security Flaw in Web or Application\",\"description\":\"What is an Open Redirect security flaw and How to Prevent it? Technical & detailed explanation of the open redirection web or application vulnerability.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/open-redirect\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"datePublished\":\"2021-03-18T12:42:10+05:30\",\"dateModified\":\"2022-12-02T13:07:25+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Open Redirect Security Flaw in Web or Application<\/title>\n\n","aioseo_head_json":{"title":"Open Redirect Security Flaw in Web or Application","description":"What is an Open Redirect security flaw and How to Prevent it? Technical & detailed explanation of the open redirection web or application vulnerability.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"Open Redirect Security Flaw in Web or Application","og:description":"What is an Open Redirect security flaw and How to Prevent it? Technical &amp; detailed explanation of the open redirection web or application vulnerability.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/check-stock-api-Request.png","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/check-stock-api-Request.png","og:image:width":"651","og:image:height":"360","article:section":"Vulnerability Disclosure","article:tag":["open redirection"],"article:published_time":"2021-03-18T07:12:10+00:00","article:modified_time":"2022-12-02T07:37:25+00:00","twitter:card":"summary_large_image","twitter:title":"Open Redirect Security Flaw in Web or Application","twitter:description":"What is an Open Redirect security flaw and How to Prevent it? Technical &amp; detailed explanation of the open redirection web or application vulnerability.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/check-stock-api-Request.png","twitter:label1":"Written by","twitter:data1":"kalpblogger","twitter:label2":"Est. reading time","twitter:data2":"2 minutes","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#article","name":"Open Redirect Security Flaw in Web or Application","headline":"Open Redirect","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/check-stock-api-Request.png","@id":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#articleImage"},"datePublished":"2021-03-18T12:42:10+05:30","dateModified":"2022-12-02T13:07:25+05:30","inLanguage":"en-US","commentCount":2,"mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#webpage"},"articleSection":"Viruses &amp; Malware, Vulnerability Disclosure, Web Application Security, Open redirection"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3\/","nextItem":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#listItem"},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#listItem","position":2,"name":"Open Redirect","previousItem":"https:\/\/www.varutra.com\/varutravrt3\/#listItem"}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/","name":"kalpblogger","image":{"@type":"ImageObject","@id":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g","width":96,"height":96,"caption":"kalpblogger"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/","name":"Open Redirect Security Flaw in Web or Application","description":"What is an Open Redirect security flaw and How to Prevent it? Technical & detailed explanation of the open redirection web or application vulnerability.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"datePublished":"2021-03-18T12:42:10+05:30","dateModified":"2022-12-02T13:07:25+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]}},"aioseo_meta_data":{"post_id":"10006","title":"Open Redirect Security Flaw in Web or Application","description":"What is an Open Redirect security flaw and How to Prevent it? Technical &amp; detailed explanation of the open redirection web or application vulnerability.","keywords":[],"keyphrases":"{\"focus\":{\"keyphrase\":\"Open Redirect\",\"analysis\":{\"keyphraseInTitle\":{\"title\":\"Focus keyphrase in SEO title\",\"description\":\"Focus keyphrase found in SEO title.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInDescription\":{\"title\":\"Focus keyphrase in meta description\",\"description\":\"Focus keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Focus keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":2},\"keyphraseInURL\":{\"title\":\"Focus keyphrase in URL\",\"description\":\"Focus keyphrase used in the URL.\",\"score\":5,\"maxScore\":5,\"error\":0},\"keyphraseInIntroduction\":{\"title\":\"Focus keyphrase in introduction\",\"description\":\"Your Focus keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInSubHeadings\":{\"title\":\"Focus keyphrase in Subheadings\",\"description\":\"Your H2 and H3 subheadings reflects the topic of your copy. Good job!\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInImageAlt\":{\"title\":\"Focus keyphrase in image alt attributes\",\"description\":\"Focus keyphrase not found in image alt attribute(s). Add an image with your Focus keyphrase as alt text.\",\"score\":3,\"maxScore\":9,\"error\":1}},\"score\":80},\"additional\":[{\"keyphrase\":\"Security Flaw\",\"score\":67,\"analysis\":{\"keyphraseInDescription\":{\"title\":\"Keyphrase in meta description\",\"description\":\"Keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":2},\"keyphraseInIntroduction\":{\"title\":\"Keyphrase in introduction\",\"description\":\"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInImageAlt\":{\"title\":\"Keyphrase in image alt attributes\",\"description\":\"Keyphrase not found in image alt attribute(s). Add an image with your Keyphrase as alt text.\",\"score\":3,\"maxScore\":9,\"error\":1}}}]}","primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"content","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/check-stock-api-Request.png","og_image_width":"651","og_image_height":"360","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Vulnerability Disclosure","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"open_ai":null,"created":"2021-10-27 15:11:40","updated":"2022-12-02 07:49:24"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/viruses-malware\/\" title=\"Viruses &amp; Malware\">Viruses &amp; Malware<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tOpen Redirect\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Viruses &amp; Malware","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/viruses-malware\/"},{"label":"Open Redirect","link":"https:\/\/www.varutra.com\/varutravrt3\/open-redirect\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/10006"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=10006"}],"version-history":[{"count":4,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/10006\/revisions"}],"predecessor-version":[{"id":20294,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/10006\/revisions\/20294"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=10006"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=10006"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=10006"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}