Open redirect TL;DR: Redirect destination is user-controlled; chains into phishing, OAuth token theft, SSRF amplification. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References https://book.hacktricks.wiki/en/pentesting-web/open-redirect.html