heroui logo

Open redirect: EWeb logout redirect

Sublime Rules

View Source
Summary
This rule detects inbound messages that contain links targeting an /eweb/ logout.aspx page where the logout redirect URL (redirecturl query parameter) points to an off-site domain rather than returning to the originating site. This indicates abuse of a legitimate logout redirect mechanism, a common tactic in credential phishing or drive-by credential capture. The detection uses inbound message content analysis to locate links with paths containing '/eweb/' and ending with 'logout.aspx', extracts the redirecturl parameter, and compares the target URL's domain/root domain to the originating site. If the redirect target is external, a potential open redirect is reported. Highly trusted sender domains are excluded unless they fail DMARC authentication to avoid unnecessary false positives. Detection methods include URL analysis (parsing and validating redirect targets) and header analysis (DMARC/auth checks). The rule is intended to mitigate phishing attempts that abuse logout redirects to lure users to attacker-controlled sites.
Categories
  • Web
  • Network
Data Sources
  • Network Traffic
  • Application Log
Created: 2026-10-02