You're almost there! Please answer a few more questions for access to the Applications content. Complete registration
Interested in joining? Complete your registration by providing Areas of Interest here. Register

redirect?target=https://www

Summary:

Security is asking why it is not blocked to use redirect?target=https://www after the subdomain? It results in vulnarabilities. What can we do about it?

Content (please ensure you mask any confidential information):

Any generic website I try on the web blocks this (results in a 404). However, when adding this behind my clients subdomain (branded) I actually get redirected. Client does not want this.

Why is this happening? And, how can I stop it?

Howdy, Stranger!

Log In

To view full details, sign in.

Register

Don't have an account? Click here to get started!