Fuzzing uri_redirect
I started with the standard redirect_uri manipulation techniques. Every single one was blocked.
Path confusion with ? and #:
https://www.company.com?/api/bin/openid/login → Rejected
https://www.company.com#/api/bin/openid/login → RejectedDomain substitution:
https://www.company.computer/api/bin/openid/login → Rejected
https://wwwa.company.com/api/bin/openid/login → RejectedAuthority injection with @:
https://www.company.com@attacker.com/api/bin/openid/login → RejectedDomain concatenation:
https://a.coma.company.computer/api/bin/openid/login → Rejected
https://a.com@.company.computer/api/bin/openid/login → Rejected
https://a.com\@.company.computer/api/bin/openid/login → RejectedEvery standard bypass was dead. The validation was solid. At this point, most hunters would move on. The redirect_uri was locked down. Nothing to see here.
But I do not give up after one round of attempts. I always push further.
Nhận xét