http://e26whn2524322mkxb3cbyk27ev2ihhq2biz35hty7gzgsyrwrygq27yd.onion/posts/blog/security/misuing-microsoft-defender-for-cloud-apps-to-bypass-outlink-protections.html
If we add a filename to our request (i.e. https://bentasker.co.uk.example.com/robots.txt ), then it'll be included in the resulting redirect <form name="hiddenform" id="hiddenform" action="https://bentasker.co.uk/robots.txt" enctype="application/x-www-form-urlencoded" method="GET"> It's not just my domain, or the .co.uk TLD either, we can even have it redirect us to Google search results: curl "https://www.google.com.example.com/search?q=does+this+search"...