cspshivam/playground
Redirect Level 4 / 6 Hard
← All labs

Parser-Confusion Bypass

An allowlist inspects the wrong slice of the URL. Exploit the gap between what it reads and where the browser goes.

Continue to your destination

This forwarder allows a redirect only if it recognises the trusted site in the target. Its parsing is sloppy — exploit that.

Must reference: cspshivam.com

This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of CSPSHIVAM Playground is not part of the target.