Pikachu-URL redirection

Unsafe url jumps
unsafe url Jump problem may occur in the implementation of all the places url address jump.
If the back-end using the front-entered the (possibly pass user parameters, or embedded in the front page before the url address) parameter as a jump destination, but do not judge if
it is possible to "jump the wrong object." The problem.
url jump more immediate hazards are:
-> Fishing, both attacker use the vulnerability party domain name (for example, a relatively well-known company domain tend to make users be assured of clicks) as a cover, and the final jump indeed phishing sites

 


 

1. page has four links,

 

 

 

2. The fourth link point to open, find its url

 

 

 

3. The i replaced by other web pages, the page jump to other designated web page,

 

 

 


 

Guess you like

Origin www.cnblogs.com/joker-vip/p/12355138.html