heroui logo

Open redirect: Staples SSO authentication

Sublime Rules

View Source
Summary
This rule detects inbound messages that include links abusing the Staples.ca SSO authentication endpoint (/sso/auth) with a Redirect_URI parameter pointing to a domain outside staples.ca. It identifies an open redirect pattern intended to make a malicious destination appear legitimate. Detection triggers when the inbound message contains a link with a root_domain of staples.ca, a path containing /sso/auth, and a Redirect_URI query parameter. It filters out false positives by excluding messages where the sender domain is staples.ca (or other highly trusted root domains) if DMARC passes, i.e., legitimate mail. It also excludes trusted senders in $high_trust_sender_root_domains when DMARC passes. The rule is focused on Credential Phishing via open redirect and brand impersonation (Staples). Detection methods include URL analysis (parsing href_url, path, and query params) and header analysis (DMARC status). The intended risk is moderate, as user interaction (clicking links) is required for credential theft, but the pattern can facilitate credential-phishing campaigns.
Categories
  • Web
  • Network
Data Sources
  • Network Traffic
Created: 2026-10-07