I'm hoping to find a security library to run the urls through prior to redirect.
I'm not a OWASP/ESAPI expert (so I could be wrong), but I don't think there is any black-box control that would magically solve any potential issues with redirects. You'll somehow have to maintain a list of what is valid. As the Open redirect page on OWASP says under "Related Controls": The server must have a relation of the authorized redirections (i.e. in a database).
In reply to Re: :OWASP ESAPI Implementation for Perl?
by Anonyrnous Monk
in thread :OWASP ESAPI Implementation for Perl?
by dannyboy1234
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |