CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester is performing an internal network assessment. They discover a web application that uses a custom API endpoint for user authentication. The application's server-side code does not properly validate user-supplied input for the 'redirect_to' parameter in the API calls. Which type of attack is MOST likely to be successful against this vulnerability?

  1. AServer-Side Request Forgery (SSRF)
  2. BOpen Redirect
  3. CSQL Injection
  4. DCross-Site Request Forgery (CSRF)
Show answer & explanation

Correct answer: B. Open Redirect

An Open Redirect vulnerability occurs when a web application accepts user-controlled input that specifies a URL to redirect to, without proper validation. This allows an attacker to craft a malicious link that redirects a victim to an arbitrary external site, often used in phishing attacks. The scenario describes exactly this condition with the 'redirect_to' parameter.

Why the other options are wrong

  • A. SSRF makes the server itself request resources from an arbitrary URL, often internal, but this scenario describes a client-side redirection issue.
  • C. SQL Injection targets database queries and is not directly related to a 'redirect_to' parameter vulnerability.
  • D. CSRF forces a user to unwittingly execute unwanted actions on a web application where they are authenticated, which is not described here.

Open Redirect

An Open Redirect vulnerability allows an attacker to redirect users to an arbitrary external URL by manipulating an unvalidated redirect parameter in a web application.

  • Exploits lack of validation on URL redirect parameters.
  • Commonly used in phishing campaigns.
  • Can lead to credential theft or malware downloads.

Memory trick: An open gate leads straight to a phishing bait.

More Attacks and Exploits questions