Site AI AuditInternet Solutions ürünü

Open Redirects: How Attackers Abuse Your Website’s Links

3 Ekim 20268 dk okumaGüvenlik ve SSL
Open Redirects: How Attackers Abuse Your Website’s Links

Short answer: An open redirect is a page on your website that forwards visitors to whatever address is given in a URL parameter, such as ?next= or ?url=, without checking it. Attackers use it to make phishing links look like they point to your trusted domain. Fix it by redirecting only to relative paths or to an allow-list of approved destinations, and by rejecting everything else.

What an open redirect is

Many websites have legitimate reasons to redirect visitors based on a parameter. After login, a site sends you back to the page you came from. A newsletter tracks clicks and then forwards you to the article. A language switcher returns you to the same page in another language. These features often work with a URL like this:

https://example.com/login?next=/account/orders

The problem starts when the code accepts any value, including full URLs on other domains:

https://example.com/login?next=https://evil.example/login

If the site blindly sends the visitor to that address, it is an open redirect. Your domain becomes a launch pad that anyone can use to send people anywhere. The weakness is listed as CWE-601 in the Common Weakness Enumeration, and the OWASP project keeps a dedicated cheat sheet on unvalidated redirects.

How attackers abuse open redirects

An open redirect does not let an attacker read your database or change your pages. Its value lies in borrowing your reputation. Typical abuses include:

The last point matters for small businesses. A “Deceptive site ahead” warning or a blocklisted domain hurts far more than the redirect itself. If that ever happens, our guide on removing the Deceptive Site Ahead warning explains the recovery.

Where open redirects usually hide

Look for any feature that takes a destination from the request. Common places are:

Custom code and older add-ons are the usual culprits. Mature platforms tend to validate their built-in redirects, but every extra plugin can bring its own. Marketing tools are worth a second look as well, because tracked links in newsletters and ads often pass through a redirect script on your domain.

How to test your site for open redirects

Only test websites you own or are authorised to test. A basic manual check takes minutes:

  1. List redirect parameters. Browse your site, log in and out, switch languages, and note every URL that contains a parameter holding a path or address.
  2. Replace the value with an external domain. Use a harmless domain you control or a reserved example domain, for example ?next=https://example.org/.
  3. Try common bypass forms. Weak filters often fail on variations such as //example.org, https:example.org, /\example.org, an encoded %2F%2Fexample.org, or https://yoursite.com.example.org.
  4. Watch where you end up. If the browser lands on the external domain, the redirect is open. Use the browser’s network panel to see the Location header.
  5. Check JavaScript redirects too. Search your front-end code for location.href, location.replace and window.open fed by URL parameters.

For larger or custom applications, open redirects are part of a proper vulnerability assessment. Our article on security scans versus penetration tests explains when you need a professional test.

How to fix an open redirect

The fix belongs in the code that performs the redirect. In order of preference:

  1. Remove the parameter. If the destination can be stored on the server, for example in the session, do that and do not accept it from the URL at all.
  2. Use identifiers instead of URLs. Pass ?dest=orders and map it to a known path on the server. Unknown identifiers fall back to a safe default page.
  3. Allow only relative paths. Accept values that start with a single / followed by a path character, and reject anything starting with // or /\, or containing a scheme like https: or javascript:.
  4. Use an allow-list for external destinations. If you must redirect to other domains, compare the parsed host exactly against a list of approved hosts. Never use “contains” or “starts with” checks on the raw string.
  5. Use framework helpers. Many frameworks and CMSs include safe redirect functions. WordPress, for example, has wp_safe_redirect(), which only allows hosts on an approved list, unlike the plain redirect function.
  6. Show an interstitial for external links. Where users genuinely post links to other sites, show a page saying “You are leaving our site” with the full destination visible.
CheckUnsafeSafe
Value typeAny URL stringKnown ID or relative path
Host validation“contains example.com”Exact match on parsed host
Protocol-relative URLsAllowedRejected
Unknown valueRedirect anywayFall back to home or account page

Prevention habits for the long run

Common mistakes when fixing open redirects

How Site AI Audit helps

Site AI Audit checks your website from the outside, the way visitors and search engines see it: the SSL certificate and its expiry, the HTTP to HTTPS redirect, security headers and exposed software versions, plus redirects and broken links found while crawling. It does not attack your application or test parameters for open redirects, which is the job of a code review or penetration test. What it gives you is a ranked list of the security basics to fix first, with plain-language instructions. You can run a free check or compare plans with monitoring on the pricing page.

Related reading

The bottom line

An open redirect turns your trusted domain into a tool for phishing and token theft. Find every place where your site redirects based on a parameter, test it with an external address, and change the code so it accepts only known identifiers, relative paths or an exact allow-list of hosts. It is usually a small fix, and it protects both your visitors and your domain’s reputation.

SSS

Is an open redirect a serious vulnerability?

On its own it is usually rated low to medium, because it does not expose your data directly. It becomes serious when combined with login or single sign-on flows, where it can leak tokens, and it can damage your domain’s reputation if used in phishing campaigns.

Do redirects in my .htaccess or server config create open redirects?

Normally not. Fixed redirects from one of your URLs to another are safe. The risk comes from redirects whose destination is taken from user input, such as a URL parameter, without validation.

Can Google penalise my site for an open redirect?

Google does not rank sites lower for having a redirect bug, but if attackers use it for phishing, Safe Browsing may flag the abused URLs and show warnings to visitors. Fixing the redirect quickly avoids that risk.

How do I test for open redirects safely?

Only test sites you own or are authorised to test. Replace the redirect parameter value with an external domain you control or a reserved example domain and see whether the browser leaves your site. Never point tests at real third-party sites.

Does WordPress protect against open redirects?

WordPress core uses safe redirect functions for its own login and admin flows. Plugins and themes, however, can implement their own redirects, so each add-on with redirect features should be tested and kept up to date.

#Redirects#Web vulnerabilities#Website security
Kendi web sitenizi kontrol edin — ücretsiz.Web sitenizde neyi düzeltmeli — ve nereden başlamalısınız?
Ücretsiz başla

Blogdan daha fazlası

Tüm makaleler →
Internet Solutions

Ekibimizden diğer ürünler

Internet Solutions tarafından geliştirildi. Diğer ürünlerimizi de deneyin — her biri size farklı bir şekilde zaman kazandırır.

internet-solutions.net ↗
Site AI Audit
Gizlilik özeti

Bu web sitesi, size mümkün olan en iyi kullanıcı deneyimini sunabilmek için çerez kullanır. Çerez bilgileri tarayıcınızda saklanır ve sitemize geri döndüğünüzde sizi tanımak, ekibimizin sitenin hangi bölümlerini en ilginç ve faydalı bulduğunuzu anlamasına yardımcı olmak gibi işlevler görür.