Do (Not) Follow the White Rabbit: Challenging the Myth of Harmless Open Redirection
Soheil Khodayari
Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Web Exploitation
Overview
This talk, presented by Gianluca Golinelli on behalf of authors Sel Kai and Gian Carlo, challenges the long-held industry belief that open redirect vulnerabilities are relatively harmless. Traditionally, these vulnerabilities, which allow an attacker to redirect a user from a legitimate site to an arbitrary malicious URL, have been deprioritized in security assessments and bug bounty programs. The research presented in this paper, titled "Do (Not) Follow the White Rabbit," argues that this perception is outdated and dangerous, especially with the modern web's increasing reliance on client-side JavaScript for handling redirections.
Key moments
- 10:40 What are dedicated URL shortening services (DUSS)?
- 12:00 The 'misdirection attack' and core research question.
- 14:00 Attacker methodology for exploiting vulnerable DUSS.
- 16:00 Types of DUSS and common security implementation flaws.
- 17:00 Research methodology to identify vulnerable DUSS APIs.
- 20:00 Key findings and significant security impact on user trust.
Do (Not) Follow the White Rabbit: Challenging the Myth of Harmless Open Redirection
Speakers: Gianluca Golinelli (Presenter, Zalando, CISPA), Sel Kai (Author), Gian Carlo (Author)
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=qaqJCCNxSSw
Overview
This talk, presented by Gianluca Golinelli on behalf of authors Sel Kai and Gian Carlo, challenges the long-held industry belief that open redirect vulnerabilities are relatively harmless. Traditionally, these vulnerabilities, which allow an attacker to redirect a user from a legitimate site to an arbitrary malicious URL, have been deprioritized in security assessments and bug bounty programs. The research presented in this paper, titled "Do (Not) Follow the White Rabbit," argues that this perception is outdated and dangerous, especially with the modern web's increasing reliance on client-side JavaScript for handling redirections.
The core of the presentation highlights how open redirects can escalate into more severe security threats, including Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and information leakage. To substantiate this claim, the researchers developed STOR, a novel framework designed to detect and analyze open redirect vulnerabilities at scale. Their findings reveal a widespread prevalence of these vulnerabilities across the web and demonstrate their significant potential for exploitation, urging a fundamental shift in how the security community perceives and addresses them.
Background
▶ Watch: What are dedicated URL shortening services (DUSS)? (10:40)
HTTP redirections are a fundamental mechanism of the web, guiding users from one resource to another. While typically handled server-side, it is still common for applications to dynamically define redirection destinations through URL parameters. When these parameters are not rigorously validated, an open redirect vulnerability emerges, enabling an attacker to manipulate the redirection target. Historically, the security community has largely dismissed open redirects as low-impact. This perspective is reflected in statistics: open redirects constitute only about 1% of all issues reported in the CVE database, a stark contrast to the 37% attributed to Cross-Site Scripting (XSS) vulnerabilities. Furthermore, many vulnerability disclosure programs from industry giants do not consider open redirect issues eligible for a reward, reinforcing the perception of their negligible threat.
However, the landscape of web development has evolved significantly. The modern web often offloads tasks, including redirections, to the client-side, executing them via JavaScript. This shift introduces a new dimension of risk, as client-side JavaScript-based redirections can be far more dangerous. They possess the potential to escalate to full-fledged XSS, CSRF, or information leakage vulnerabilities. For instance, an attacker could inject a javascript: scheme followed by malicious code into a redirect parameter, effectively triggering an XSS vulnerability. This capability fundamentally undermines the "harmless" myth surrounding open redirects.
Previous attempts to detect these vulnerabilities suffered from significant limitations. One approach involved identifying vulnerability indicators – specific URL patterns or parameters that suggest the presence of an open redirect. While lightweight and immediately noticeable, this method relies on a handcrafted, comprehensive list of indicators, which is inherently challenging to maintain and often incomplete. Another strategy involved using static analysis to scrutinize client-side JavaScript code. However, this approach is computationally intensive and costly, necessitating page sampling strategies to manage the analysis burden, thereby limiting its scalability and comprehensiveness. The need for a more efficient, scalable, and accurate methodology to detect and evaluate the impact of open redirects became evident, forming the impetus for the research presented in this talk.
Key Findings
▶ Watch: Attacker methodology for exploiting vulnerable DUSS. (14:00)
The research presented in "Do (Not) Follow the White Rabbit" unveiled several critical findings that collectively challenge the long-standing underestimation of open redirect vulnerabilities. The development of the STOR framework was central to these discoveries, providing a scalable and efficient means to identify and analyze these issues across a vast swathe of the internet.
Key findings include:
- Widespread Prevalence: Open redirect vulnerabilities are far more common than previously assumed, affecting approximately 9% of all websites analyzed in the study. This statistic alone underscores the significant and overlooked attack surface they represent.
- Escalation to Critical Vulnerabilities: The most impactful finding is the demonstrated potential for open redirects to escalate to more severe attack classes. Specifically, 10% of the identified open redirects could be exploited for Cross-Site Scripting (XSS) attacks. An additional 3% were found to be exploitable for Cross-Site Request Forgery (CSRF) or information leakage attacks. This directly refutes the notion that open redirects are low-impact.
- Novel Detection Methodology (STOR): The STOR framework successfully combined static analysis with runtime monitoring to achieve a cost-effective and scalable approach to detecting open redirects. This methodology proved capable of identifying vulnerabilities that traditional methods might miss.
- Comprehensive Indicator Catalog: The study yielded a catalog of 184 concrete vulnerability indicators, organized into nine distinct categories. This catalog was distilled from the analysis of over 20,400 confirmed vulnerable URLs across 59 websites. This resource represents a significant contribution to the community, providing a robust set of patterns for identifying potential open redirects.
- Efficiency of Indicators: The research demonstrated that using these indicators is remarkably efficient. Indicator-based detection was found to be over 100 times faster and required 590 times less storage than purely static analysis methods. While indicators may suffer from false negatives due to the optional nature of URL parameters, their speed makes them invaluable for initial, large-scale scanning.
- Discovery of New Vulnerabilities: Utilizing the generated indicator catalog, STOR successfully mined 375 new open redirect vulnerabilities across 326 unique websites. Of these, 202 were client-side vulnerabilities, and 171 were server-side, highlighting the dual nature of the threat.
- Higher Escalation Rate for Indicator-Based Findings: Interestingly, open redirects identified using the indicator catalog showed a higher escalation rate to XSS (22%) compared to those found solely via static analysis (8%). This suggests that certain patterns or types of open redirects, more easily captured by indicators, might inherently possess greater exploitability potential.
These findings collectively paint a picture of open redirects as a pervasive and underestimated threat, necessitating a re-evaluation of their security implications and a more proactive approach to their detection and mitigation.
Technical Deep Dive
▶ Watch: Types of DUSS and common security implementation flaws. (16:00)
The core innovation of this research lies in the STOR framework, a novel cost-reduction methodology designed for the systematic study and mining of open redirect vulnerabilities at scale. STOR cleverly combines the strengths of static analysis with runtime monitoring to overcome the limitations of previous detection approaches.
The framework operates through a multi-stage process:
- Data Collection: STOR's input is a substantial dataset of web page snapshots. For this research, over 1 million pages across 10,000 different applications and websites were collected in October 2022 using browser automation tools like Playwright and Fox. This comprehensive dataset was then partitioned: one segment was dedicated to the extraction of vulnerability indicators, while the other was reserved for testing and validation.
- Candidate Vulnerability Detection (Static Analysis): In the initial phase, STOR employs static analysis to examine the client-side JavaScript code of each web page. The tool Joe was utilized for this purpose, identifying potential open redirect vulnerabilities by analyzing how URLs are constructed and manipulated within the JavaScript code. This step pinpoints candidate locations where user-controlled input might influence redirection logic.
- Vulnerability Validation (Runtime Monitoring): Merely identifying candidates through static analysis is insufficient due to potential false positives. Therefore, STOR incorporates runtime monitoring tests to dynamically validate these candidates. This involves submitting crafted URLs to the identified endpoints and observing the actual redirection behavior in a controlled environment, confirming whether an open redirect indeed occurs.
- Indicator Extraction: Confirmed vulnerable URLs are then grouped and analyzed to distill common patterns. This process leads to the creation of a catalog of vulnerability indicators. These indicators are essentially signatures or characteristics of vulnerable redirect mechanisms, such as specific parameter names (e.g.,
redirect,next,return_to), URL schemes, or domain manipulation techniques. To ensure comprehensiveness, the authors also manually reviewed relevant entries from the CVE database to include indicators associated with known server-side open redirect vulnerabilities. This meticulous process resulted in a catalog of 184 concrete vulnerability indicators categorized into nine different types.
- Large-Scale Mining: With the robust catalog of indicators in hand, STOR moves to its large-scale mining phase. It collects additional candidate vulnerable URLs by matching them against the indicators. This is done across the remaining "left-out" snapshots from the original dataset, through Google search via Dorking (using specific search queries to find URLs matching indicators), and by querying the Internet Archive. Each of these newly identified candidate URLs is then subjected to the same rigorous runtime monitoring tests for validation. This systematic approach led to the discovery of 375 new open redirect vulnerabilities across 326 websites.
- Escalation Verification: A critical aspect of STOR is its ability to verify the potential for escalation to more severe vulnerability classes. All 21,000 detected open redirects (from both initial detection and mining phases) were systematically tested using a dictionary of dynamic XSS payloads. This involved injecting various JavaScript snippets into the redirect parameter to determine if they could execute arbitrary code. Additionally, a random selection of two vulnerabilities per site was manually vetted for Cross-Site Request Forgery (CSRF) and information leakage potential, providing a qualitative assessment of exploitability beyond automated checks. The ability to escalate to XSS was demonstrated using a minimal example where a
javascript:scheme combined with arbitrary JavaScript code injected into a redirect parameter could trigger an XSS vulnerability, showcasing the direct link between an open redirect and more critical attacks.
The performance evaluation further highlighted STOR's efficiency. When comparing indicator-based detection against purely static analysis on a dataset of 42,000 web pages across 50 random applications:
- Static analysis identified 46 true open redirects from 8 applications but had a 20% false positive rate.
- Indicators identified 16 true vulnerabilities across 6 applications with no false positives.
Crucially, indicators proved complementary, identifying 5 vulnerabilities that static analysis had overlooked. While static analysis provided broader coverage, indicators were significantly faster and lighter, demonstrating the value of their combined approach in STOR.
Demo / Proof of Concept
▶ Watch: Research methodology to identify vulnerable DUSS APIs. (17:00)
While the presentation did not feature a live, interactive demonstration of a specific exploit, the research methodology itself served as a large-scale, systematic proof of concept. The talk explicitly referenced a slide that illustrated a "minimal Cross-Site Scripting vulnerability triggerable through the redirect parameter, the JavaScript scheme and some arbitrary JavaScript code." This visual example served to conceptually demonstrate how an open redirect, particularly in client-side contexts, could be leveraged for XSS.
Furthermore, the paper's rigorous verification process effectively functioned as an extensive, automated proof of concept. The researchers tested all 21,000 detected open redirects using a "dictionary of dynamic XSS payloads." This involved programmatically attempting to inject malicious JavaScript through the redirect parameters to confirm if arbitrary code execution was possible. In addition, a selection of "two vulnerabilities per site were randomly selected to be manually vetted against request forgery or information leaking vulnerabilities." This systematic, evidence-based approach provided empirical proof of the exploitability and severity of the identified open redirect vulnerabilities across a broad spectrum of websites, validating the core hypothesis of the research without requiring a live, single-instance demo.
Defensive Implications
▶ Watch: Key findings and significant security impact on user trust. (20:00)
The findings presented in "Do (Not) Follow the White Rabbit" necessitate a fundamental shift in how organizations and developers perceive and mitigate open redirect vulnerabilities. No longer can these issues be dismissed as harmless; their potential for escalation to critical attacks demands immediate attention.
Defenders should adopt the following strategies:
- Re-evaluate Open Redirect Severity: Organizations must update their internal security policies, risk assessments, and bug bounty programs to recognize open redirect vulnerabilities as potentially high-impact, especially when coupled with client-side JavaScript or the ability to inject arbitrary schemes. Rewarding their discovery can incentivize researchers to find and report them.
- Implement Strict Input Validation for Redirect Parameters: This is paramount. Any URL parameter used for redirection, whether server-side or client-side, must undergo stringent validation.
- Whitelisting: The most robust defense is to whitelist acceptable redirect destinations. This means only allowing redirections to a predefined, static list of trusted domains or specific paths within the application's domain. Wildcards should be used with extreme caution and precision.
- Scheme Validation: Prohibit or strictly validate URL schemes. Explicitly disallow dangerous schemes like
javascript:,data:, orfile:in redirect parameters. Onlyhttp:andhttps:should generally be permitted. - Path Validation: Ensure that any user-supplied path components do not lead outside the intended application scope.
- Sanitize All User-Supplied Redirect Data: Before using any user-supplied string in a redirection, ensure it is properly sanitized and encoded to prevent injection attacks. This includes URL encoding of path and query components.
- Client-Side Redirection Awareness: Developers frequently implement client-side redirections using JavaScript, often with
window.location.href = user_input;or similar constructs. This practice is inherently risky. Developers should be acutely aware of the potential for XSS when dynamically constructing URLs from untrusted input in JavaScript. If client-side redirection is unavoidable, the same stringent validation and sanitization rules as server-side should apply. Consider using a server-side redirect where possible, as it's often easier to secure. - Utilize Advanced Detection Tools: Security teams should leverage or develop tools that incorporate methodologies similar to the STOR framework. This means combining static analysis of client-side code with dynamic runtime monitoring to detect open redirects comprehensively and at scale. The catalog of 184 vulnerability indicators produced by this research can be integrated into automated scanners to improve their efficiency in identifying potential targets.
- Regular Security Audits and Penetration Testing: Conduct frequent security audits and penetration tests that specifically target open redirect vulnerabilities, actively attempting escalation scenarios (XSS, CSRF, information leakage).
- Educate Developers: Continuously educate developers on the risks associated with open redirects, the nuances of client-side redirection, and secure coding practices for handling URL parameters.
By adopting these defensive measures, organizations can move beyond the "harmless" myth and proactively secure their web applications against the pervasive and potentially damaging threat of open redirect vulnerabilities.
Key Takeaways
- Open Redirects Are Not Harmless: The prevailing notion that open redirect vulnerabilities are low-impact is fundamentally flawed and dangerous. They are a significant and often underestimated threat.
- Widespread Prevalence: Open redirects are pervasive, affecting approximately 9% of all websites, indicating a large and unaddressed attack surface.
- High Escalation Potential: A substantial portion of open redirects can be escalated to more severe attacks: 10% to Cross-Site Scripting (XSS) and an additional 3% to Cross-Site Request Forgery (CSRF) or information leakage.
- Client-Side Risks Magnified: The rise of client-side JavaScript-based redirections significantly amplifies the risk, making open redirects a direct vector for XSS and other client-side attacks.
- STOR Framework for Scalable Detection: The novel STOR framework provides an efficient and cost-effective methodology for detecting open redirect vulnerabilities at scale by combining static analysis and runtime monitoring.
- Valuable Indicator Catalog: The research produced a catalog of 184 concrete vulnerability indicators across 9 categories, which can greatly improve the efficiency of automated detection tools.
- Urgent Call to Action: Developers and security teams must re-evaluate open redirects, implement strict input validation (especially whitelisting and scheme validation), and update security policies and bug bounty programs to reflect their true severity.
About the Speaker(s)
The paper "Do (Not) Follow the White Rabbit: Challenging the Myth of Harmless Open Redirection" was presented by Gianluca Golinelli from Zalando and CISPA. He stepped in to present the work on behalf of the paper's authors, Sel Kai and Gian Carlo. While the transcript does not provide specific titles or affiliations for the authors, Gianluca Golinelli's role as a presenter from Zalando and CISPA indicates his involvement in cutting-edge security research within both industry and academia.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Legitimate academic research that rehabilitates open redirect from 'won't fix' territory with real data — 1M pages, 21K confirmed vulns, 184 indicators, measurable escalation rates. Solid empirical work, but the core insight (javascript: scheme in a redirect parameter → XSS) isn't new to anyone who's done web sec seriously, and the paper's contribution is more measurement than novel attack primitive.
Heather Calloway (CISO) — WEAK
Credible research that successfully challenges the underclassification of open redirect vulnerabilities, with real empirical weight behind the claim. But it stops at the technical layer — the gap between 'this is more dangerous than you think' and 'here is how your organization should govern, triage, or reprioritize it' is never closed.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025