> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/zh/web/dom/dom-based-open-redirection.md).

# 基于 DOM 的开放重定向

### 基于 DOM 的开放重定向

此实验在 DOM 端存在开放重定向漏洞。目标是利用该漏洞将受害者重定向到攻击服务器。

**易受攻击的片段（返回博客按钮）**/ 评论区中与该按钮关联的动作代码是：

{% code overflow="wrap" %}

```javascript
onclick='returnUrl = /url=(https?:////.+)/.exec(location); location.href = returnUrl ? returnUrl[1] : "/"'
```

{% endcode %}

<figure><img src="/files/5b6b884a923eb6e0b8a6827a3f5556797727ea14" alt=""><figcaption></figcaption></figure>

此脚本提取一个 `URL` 参数，使用正则表达式从当前 URL 中提取该参数，如果存在则重定向到其值；否则返回根目录（`/`).

**工作原理**/ 只需添加 `&URL=<target>` 到帖子 URL 中。当用户点击“返回博客”时，脚本会获取该参数，浏览器将被重定向到所提供的目标地址。

**URL 示例**

{% code overflow="wrap" %}

```
https://0a9700fa04b783118073038f00bc00eb.web-security-academy.net/post?postId=1&url=https://jord4n.pro
```

{% endcode %}

* — 加载后，点击返回博客会重定向到 `https://jord4n.pro`.

<figure><img src="/files/0a7fb5bb29f7c91345f296093c08fd31d2026c53" alt=""><figcaption></figcaption></figure>

用于实验（直接跳转到攻击服务器）：

{% code overflow="wrap" %}

```
https://0a9700fa04b783118073038f00bc00eb.web-security-academy.net/post?postId=1&url=https://exploit-0abf00fb04aa83b480d502ca019900d1.exploit-server.net/
```

{% endcode %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/zh/web/dom/dom-based-open-redirection.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
