← Back to list

How I found Open redirect on Bug crowd public program in 2 day

Tools : - Burp suite - Burp JS Link Finder

Ittipatjitrada · 2022-07-06 07:16 · 122 claps · 1.6 min read
#bug-bounty #bug-bounty-tips #bugcrowd #open-redirect #public-programs
Open on Medium ↗

How I found Open redirect on Bug crowd public program in 2 day

Tools :

  • Burp suite
  • Burp JS Link Finder

Explain :

First of all, I chose to make this program because it has a new update so I want to do it. On that first day, I didn’t find anything like many programs I’ve done. Then on the second day I started to think about where to go next. I remember at first I chose to look for the endpoint a bit more but in the end I couldn’t find anything. I remember I had a burp JS Link finder extension. After searching for a while I found an endpoint similar to that main endpoint is /n/ endpoint and primary endpoint is /s/.

Then I go into the endpoint. Then I found that it was an old web page. The first thing I thought I would do was go through some old scripts that the dev might have forgotten to remove. And then I found out that there is a script that can cause an open redirect vulnerability.

After that I managed to copy endpoint found, use it and change the value to evil.com


메타데이터
post_id
a217cfb70f3
slug
how-i-found-open-redirect-on-bug-crowd-public-program-in-2-day-a217cfb70f3
url
https://medium.com/@ittipatjitrada_72022/how-i-found-open-redirect-on-bug-crowd-public-program-in-2-day-a217cfb70f3
canonical_url
https://medium.com/@ittipatjitrada_72022/how-i-found-open-redirect-on-bug-crowd-public-program-in-2-day-a217cfb70f3
author_url
https://medium.com/@ittipatjitrada_72022
status
ok
fetched_at
2026-06-09 15:37:30