Malware
Open redirect
Open redirect is a URL on a trusted site that forwards the visitor to whatever address a query parameter supplies. It lends the site's good name to a link that ends somewhere hostile.
How it is measured
Test every endpoint that redirects: login return paths, logout, link trackers, language switchers. Add a parameter such as ?next=https://example.org or //example.org and read the Location header. If the response sends the browser to the foreign host, the endpoint is open.
Also try variants that slip past naive checks: //host, a host placed after an @ sign, or a hostname that merely starts with your domain, like trusted.example.attacker.test. Count how many distinct endpoints accept them.
Worked example
A university's login page accepts /login?return=URL. A phishing mail links to the university's real hostname with return pointing at a lookalike, sso-universty.example. The domain at the start of the link is genuine; after sign-in, the student is silently sent to a clone that asks for the password again.
The fix is to accept only relative paths or a list of exact hostnames. The security team also finds /go?u= on the library site doing the same thing, a click counter nobody had audited since 2016.
How it differs
Phishing is the deception: a message or page that impersonates someone. An open redirect is a flaw that makes the deception more believable by putting a legitimate hostname at the front of the link. The redirect is a bug in your app; the phish is somebody else's campaign that uses it.
Common errors
Checking the parameter with startsWith or a substring match on your domain. Blocking http:// but allowing // URLs. Logging redirects without validating them. Rating it low severity because the site itself was not breached. Forgetting redirect parameters in OAuth callbacks.
In practice
Search your code for redirects and location assignments that take user input. Switch to an allowlist of paths or hosts, return an error for anything else, and test with the odd URL forms above. For OAuth, require exact matching of registered redirect URIs.