Open redirect

URL that can be used to redirect to an arbitrary second URL.

An open redirect is a URL that redirects to a second URL which is read from the first URL's query string and which can be modified to make the redirect go to an arbitrary website.

For example, the server at example.com could be set so that any URL of the type www.example.com/redirect?url=secondwebsite.com would redirect to secondwebsite.com no matter what that site was - this would be an open redirect.

Open redirects are popular among webmasters for monitoring the links users are clicking on: before the user is redirected, their 'click' is registered in a database. However, open redirects have become popular among spammers too, who send emails containing open redirects and thus circumventing spam filters that blacklist certain URLs. Popular websites such as Google and LinkedIn are known to use or have used open redirects.

Although an open redirect does not harm the site itself, webmasters should avoid using them due to the fact that they help spammers, could cause increased and unwanted traffic to the site and could eventually lead to their own site being blacklisted. Clicked links can be monitored for example by only allowing redirects to certain URLs or by using numbers that correspond to entries in a database with links instead of URLs.

Related news articles

Spammers turn to DoubleClick for open redirect

Loophole in Google's AdSense solved, but new flaw quickly uncovered.

03 June 2008

  see all related news stories


Poll

Do you use the same password(s) across multiple websites?
I use the same password for all sites
I have a number of passwords but use the same for some sites
I use a different password for each site
I don't sign up to any sites that require a password

Leave a comment
View 4 comments

Jobs Recruit Sidebar

Virus Bulletin

In this month's magazine:
  • Social networking meets social engineering
  • Flying solo
  • Geneva convention
  • 7th German Anti Spam Summit 2009
  • Anti-phishing landing page: turning a 404 into a teachable moment
  • An update on spamming botnets: are we losing the war?
  • Windows Server 2008 Standard Edition SP2 x86
Virus Bulletin 10 2009
Subscribe now!
Virus Bulletin currently has 190,946 registered users.