Fuzzing uri_redirect
I started with the standard redirect_uri manipulation techniques. Every single one was blocked. Path confusion with ? and # : https://www.company.com?/api/bin/openid/login → Rejected https://www.company.com#/api/bin/openid/login → Rejected Domain substitution: https://www.company.computer/api/bin/openid/login → Rejected https://wwwa.company.com/api/bin/openid/login → Rejected Authority injection with @ : https://www.company.com@attacker.com/api/bin/openid/login → Rejected Domain concatenation: https://a.coma.company.computer/api/bin/openid/login → Rejected https://a.com@.company.computer/api/bin/openid/login → Rejected https://a.com\@.company.computer/api/bin/openid/login → Rejected Every standard bypass was dead. The validation was solid. At this point, most hunters would move on. The redirect_uri was locked down. Nothing to see here. But I do not give up after one round of attempts. I always push further.