Open redirects lend trusted domains to phishing
A redirect that will send users anywhere lets an attacker send a link that genuinely starts at your domain.
The victim checks the address, sees your name, clicks, and arrives somewhere else. Nothing on your site was compromised; you have simply lent your credibility. It is usually dismissed as low severity and is a significant multiplier for phishing against your own customers.
More on Web application security
- CSRF abuses an authenticated browserTheir note, your session
- XSS turns trusted pages into script deliveryIt comes out in your own voice
- Output encoding is context-specificThe plug has to match the socket
- Path traversal escapes the intended file areaTwo dots at a time
- File upload security is more than extension checkingThe label is a claim, not a check
- Security headers shape browser behaviourInstructions the browser follows
