BugScanTeam/BugRequest

更精准的url跳转

Opened this issue · 0 comments

howmp commented

类似这样的url中,并没有url,u等参数,但确实是跳转的。

https://lab.alipay.com/user/navigate.htm?goto=https%3A%2F%2Flab.alipay.com%3A443%2Fuser%2Fnavigate.htm%3Freferer%3Dhttps%253A%252F%252Fauth.alipay.com%252Flogin%252FhomeB.htm%253FredirectType%253Dparent

所以应该判断其url参数中是否包含一个网址,与最终跳转网站是否一致/相似