0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

【27個目】【DOM XSS】 DOM-based open redirection

Posted at

DOM-based open redirection

概要

オープンリダイレクト脆弱性を利用して、エクスプロイトサーバへのリンクを作成する

攻撃手順

  • オープンリダイレクト脆弱性があるブログ投稿画面からホーム画面へ遷移するリンクを確認
  • onclickの処理をみて、クエリパラメタ作成
<a href="#" onclick="returnUrl = /url=(https?:\/\/.+)/.exec(location); location.href = returnUrl ? returnUrl[1] : &quot;/&quot;">Back to Blog</a>

対策

  • エスケープ処理を行う

クリアするまでにかかった時間

  • 30m
0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?