From 31e7979962d67ea04bb7de4398021212d3cf2e09 Mon Sep 17 00:00:00 2001 From: Sam Scholten Date: Wed, 18 Oct 2023 15:55:59 -0400 Subject: [PATCH 1/3] New Insight: Open Redirect Destinations --- insights/links/open_redirect_destinations.yml | 7 +++++++ 1 file changed, 7 insertions(+) create mode 100644 insights/links/open_redirect_destinations.yml diff --git a/insights/links/open_redirect_destinations.yml b/insights/links/open_redirect_destinations.yml new file mode 100644 index 00000000000..27cf278db31 --- /dev/null +++ b/insights/links/open_redirect_destinations.yml @@ -0,0 +1,7 @@ +name: "Open redirect destinations" +type: "query" +source: | + map(filter(body.links, any(.href_url.rewrite.encoders, strings.ends_with(., "_open_redirect"))), .href_url.url) +severity: "medium" +tags: + - "Links" From c70dfac9ad03d39c44540dce41c23ab53b64c5f6 Mon Sep 17 00:00:00 2001 From: Sam Scholten Date: Wed, 18 Oct 2023 16:00:32 -0400 Subject: [PATCH 2/3] Update open_redirect_destinations.yml --- insights/links/open_redirect_destinations.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/insights/links/open_redirect_destinations.yml b/insights/links/open_redirect_destinations.yml index 27cf278db31..4d225e252d5 100644 --- a/insights/links/open_redirect_destinations.yml +++ b/insights/links/open_redirect_destinations.yml @@ -1,4 +1,4 @@ -name: "Open redirect destinations" +name: "Open redirect effective URLs" type: "query" source: | map(filter(body.links, any(.href_url.rewrite.encoders, strings.ends_with(., "_open_redirect"))), .href_url.url) From 3aa8556211ec6771ff89e77653c338092ece2460 Mon Sep 17 00:00:00 2001 From: Sam Scholten Date: Thu, 7 Mar 2024 15:24:40 -0500 Subject: [PATCH 3/3] Update open_redirect_destinations.yml --- insights/links/open_redirect_destinations.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/insights/links/open_redirect_destinations.yml b/insights/links/open_redirect_destinations.yml index 4d225e252d5..a828f43299a 100644 --- a/insights/links/open_redirect_destinations.yml +++ b/insights/links/open_redirect_destinations.yml @@ -1,7 +1,7 @@ name: "Open redirect effective URLs" type: "query" source: | - map(filter(body.links, any(.href_url.rewrite.encoders, strings.ends_with(., "_open_redirect"))), .href_url.url) + map(filter(body.links, any(.href_url.rewrite.encoders, strings.contains(., "open_redirect"))), .href_url.url) severity: "medium" tags: - "Links"