Clever #BugBountyTip from @bugraeskici: if you stumble upon a URL whitelist, try special characters (like ğ). Some parsers can& #39;t render them and change it to "?", allowing URL whitelist bypass!
Shoutout to @samwcyo, who tweeted out something similar before:
https://twitter.com/samwcyo/status/1246997498981494784?s=21">https://twitter.com/samwcyo/s... https://twitter.com/samwcyo/status/1246997498981494784">https://twitter.com/samwcyo/s...
https://twitter.com/samwcyo/status/1246997498981494784?s=21">https://twitter.com/samwcyo/s... https://twitter.com/samwcyo/status/1246997498981494784">https://twitter.com/samwcyo/s...