-
first hit the website : localhost(your ip)
-
then go to OWASP MUTILIDAE II

-
then owasp 2013 → A10-Unvalidated redirects → Credits

-
click OWASP


-
intercept on → refresh the same page → then go to proxy → http history → then got the index.php url → right click and send to repeater

-
then edit the orl to www.evil.com and then SEND

-
then do right click → show response in browser

-
then copy the url and paste it the burp's browser

- you wiill see this page
