Homakov on Covert Redirect OAuth exploit(homakov.blogspot.com.ar)
homakov.blogspot.com.ar
Homakov on Covert Redirect OAuth exploit
http://homakov.blogspot.com.ar/2014/05/covert-redirect-faq.html
http://homakov.blogspot.com.ar/2014/05/covert-redirect-faq.html
- http://foo.com - http://foo.com/foo
Facebook accepts redirects like: - http://foo.com?anything_here=xx
And if the client has an open redirect, some query string to redirect anywhere combined with response_type token.. the evil website can get the token.