Loop of Doom: How a Recursive Redirect Opened the Gates to Session Hijacking ♻️
作者在调试循环重定向时发现了一个开放重定向漏洞,并通过注入恶意链接尝试 hijack session。尽管初始测试被阻止,但最终导致了递归重定向的 nightmare。 2025-8-10 05:38:9 Author: infosecwriteups.com(查看原文) 阅读量:19 收藏

Iski

Free Link 🎈

Hey there!😁

Press enter or click to view image in full size

image by AI

“You ever chase your tail so hard you forgot what you were chasing? That was me, debugging a loop of redirects at 3 AM with coffee in one hand and existential dread in the other.”

Let me tell you the tale of how a harmless-looking redirect turned into a recursive nightmare that allowed me to hijack a session and almost broke my brain in the process.

During a weekend recon rabbit hole, I found a juicy subdomain with a login flow that was trying way too hard to look secure. JavaScript-heavy, token-based auth, fancy OAuth flows… you name it.

I started hunting for open redirects just to pass time.

A typical payload I use:

https://example.com/login?redirect=https://evil.com

That got blocked instantly — they were validating redirect hosts.


文章来源: https://infosecwriteups.com/loop-of-doom-how-a-recursive-redirect-opened-the-gates-to-session-hijacking-%EF%B8%8F-705417f3e741?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh