Are Open Redirects A Security Concern?


Answer :

YES, and its an OWASP top 10 violation: OWASP A10 - Unvalidated Redirect. These are valuable for phishing and spam. Recently it was uncovered that spammers where exploiting Open Redirect vulnerabilities on US .gov websites for profit.


Comments

Popular posts from this blog

Are Regular VACUUM ANALYZE Still Recommended Under 9.1?

Can Feynman Diagrams Be Used To Represent Any Perturbation Theory?