Overview
Application redirects user to attacker-controlled URL via unvalidated parameter. Used for phishing, OAuth token theft, and SSRF chain.Common Parameters
Detection
evil.com.
Bypass Techniques
Double URL Encoding
Using @ Symbol
user@host — actual destination is evil.com.