Hacker News new | ask | show | jobs
by Rauchg 504 days ago
It’s possible `/` redirects but other hidden routes phish. If someone gets e.g.: a fake password reset email, it might help the attacker bypass sanity checks users make.
1 comments

Also helps create phishing report "false" flags.

If I target a specific region with a phishing link and redirect if the requestor is not in that region I can probably maintain my phishing domains for longer.