Page 1 of 2

lexmark.com Open Redirect

Posted: Tue Dec 22, 2015 9:32 pm
by Spam404Online
I submitted an open redirect for lexmark.com and it didn't go through, was there an issue?

Re: lexmark.com Open Redirect

Posted: Wed Dec 23, 2015 4:57 am
by Spam404Online
It appears my one for connect.bloomberg.com didn't go through either, any help?

Re: lexmark.com Open Redirect

Posted: Wed Dec 23, 2015 5:04 am
by Spam404Online
Looks like ilms.intel.com too :(

Re: lexmark.com Open Redirect

Posted: Wed Dec 23, 2015 5:10 am
by x1admin
all approved

Re: lexmark.com Open Redirect

Posted: Wed Dec 23, 2015 5:11 am
by Spam404Online
x1admin wrote:all approved
Awesome as always, thank you :D

Re: lexmark.com Open Redirect

Posted: Wed Dec 23, 2015 9:52 am
by Spam404Online
Some more seem to require manual approval -

getcopy.edina.ac.uk
adobe.com
dotrural.ac.uk
worldweather.wmo.int

All open redirects :)

Re: lexmark.com Open Redirect

Posted: Thu Dec 24, 2015 5:51 am
by x1admin
Spam404Online wrote:Some more seem to require manual approval -

getcopy.edina.ac.uk
adobe.com
dotrural.ac.uk
worldweather.wmo.int

All open redirects :)
all approved

Re: lexmark.com Open Redirect

Posted: Thu Dec 31, 2015 12:21 am
by _Dlso
My XSS for amp.com.au didn't get approved :(
The following open-redirects didn't approved either:
http://gamefa.com/go.php?http://xssposed.org/
http://www.rusdoc.ru/go.php?http://xssposed.org/
http://tourlib.net/go.php?url=http://xssposed.org/
https://www.mail.cloud9.net/services/go ... posed.org/
http://www.alstel.net/go.php?url=http://xssposed.org/

And an XSS on http://www.internetofficer.com/seo-tool/redirect-check/ (Post Data: url=%3Cimg+src%3Dx+onerror%3Dprompt%28%2FXSSPOSED%2F%29%3E&Request=Check+Redirects)

Re: lexmark.com Open Redirect

Posted: Fri Jan 01, 2016 5:24 pm
by Lewis
Spam404Online wrote:Some more seem to require manual approval -

getcopy.edina.ac.uk
adobe.com
dotrural.ac.uk
worldweather.wmo.int

All open redirects :)
did you try contacting adobe for theirs? You could potentially get a HOF mention or something bigger from it I reckon :)

Re: lexmark.com Open Redirect

Posted: Fri Jan 01, 2016 8:27 pm
by Spam404Online
Lewis wrote:did you try contacting adobe for theirs? You could potentially get a HOF mention or something bigger from it I reckon :)
Submitted it to them through HackerOne on December 23rd and since then it's been triaged :D