Documentation
README
Open Redirect
Objective
Exploit URL redirect parameters to redirect users to attacker-controlled domains, steal OAuth tokens, or bypass security controls.
Testing Methodology
Phase 1: Identify Redirect Parameters
Common parameter names:
url, redirect, redirect_url, redirect_uri, return, return_url, returnTo,
next, goto, target, dest, destination, rurl, redir, forward, continue,
callback, path, out, view, login_url, image_url, go, link, ref
Phase 2: Basic Payloads
This is the opening of the README. Read the full README on GitHub.