From e9de4e9d78b87fbff64b71b2db2ed73e726f195b Mon Sep 17 00:00:00 2001 From: Cervoise Date: Thu, 26 Nov 2020 16:43:10 +0100 Subject: [PATCH] Update README.md Add the "?" trick. --- Open Redirect/README.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/Open Redirect/README.md b/Open Redirect/README.md index d74315f..ec2cfb7 100644 --- a/Open Redirect/README.md +++ b/Open Redirect/README.md @@ -114,6 +114,14 @@ http://www.yoursite.com/http://www.theirsite.com/ http://www.yoursite.com/folder/www.folder.com ``` +Using "?" characted, browser will translate it to "/?" + +```powershell +http://www.yoursite.com?http://www.theirsite.com/ +http://www.yoursite.com?folder/www.folder.com +``` + + Host/Split Unicode Normalization ```powershell https://evil.c℀.example.com . ---> https://evil.ca/c.example.com