heroui logo

Open redirect: Quickbase

Sublime Rules

View Source
Summary
This rule detects inbound emails that contain links to quickbase.com which abuse Quickbase's redirect functionality by using an API parameter together with a redirect parameter (rdr=) that points to a destination outside of quickbase.com. The intent is to disguise malicious URLs as legitimate Quickbase redirects and facilitate credential phishing or other user deception. Detection triggers when a link in the email has href_url.domain.root_domain == "quickbase.com" and the query parameters include both 'a=API_' and 'rdr='; it further ensures the redirect target is not itself a quickbase.com URL (prevents false positives where the redirect stays within Quickbase). To reduce false positives, the rule excludes emails from quickbase.com or other domains that pass DMARC authentication, and excludes high-trust sender domains that pass DMARC. Detection methods rely on URL analysis (query parameter inspection, domain checks) and header analysis (DMARC authentication status). The rule is categorized under the Open redirect technique and aligned with Credential Phishing attacks.
Categories
  • Web
  • Network
Data Sources
  • Network Traffic
Created: 2026-10-07