Open Redirect login account

Disclosed: 2014-08-25 21:58:02 By jaysonzabate To slack
Unknown
Vulnerability Details
An open redirect is an application that takes a parameter and redirects a user to the parameter value without any validation. This vulnerability is used in phishing attacks to get users to visit malicious sites without realizing it. ###Reproduction Instructions go to `www.[TEAM].slack.com/?redir=llink?url=https://twitter.com/` log in your account on this link then redirect to twitter,google and any webiste you want. ###Proof of concept: ``` https://asdasda.slack.com/?redir=llink?url=https://twitter.com/ ``` Regards, Jayson Zabate
Actions
View on HackerOne
Report Stats
  • Report ID: 16718
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report