heroui logo

Open Redirect: emlakarsa

Sublime Rules

View Source
Summary
This rule is designed to detect open redirect vulnerabilities specifically associated with the domain 'emlakarsa.net'. It identifies messages that contain links pointing to this domain and utilize parameters related to setting language and redirection. The detection logic checks if the message sender's domain is not 'emlakarsa.net' and evaluates the sender's profile for unsolicited messages or those known to be malicious, while ensuring that any highly trusted sender domains are only flagged if they fail DMARC authentication. The rule targets email scenarios where attackers may exploit legitimate-looking links to redirect users, potentially exploiting the open redirect for credential phishing or malware delivery.
Categories
  • Web
  • Application
  • Identity Management
Data Sources
  • User Account
  • Web Credential
  • Network Traffic
Created: 2024-09-09