DOM-based Open Redirect Phishing

Abusing trusted application domains to forward victims to malicious endpoints via unvalidated JavaScript sinks.

The Phishing Link Formulation:

The link looks authentic because it starts with the victim's domain, but the JS logic handles the final bounce to the fake page.

https://webapp.kr-rezvan.ir/redirect-gateway?forward=https://hackerapp.eitebar.ir/fake-login
Test Open Redirect Attack