Oauth2.0 协议说明如下: https ://www.rfc-editor.org/rfc/rfc6749#section-10.6
When the attacker's user-agent is sent to the authorization server to grant access,
the attacker grabs the authorization URI provided by the legitimate client and replaces
the client's redirection URI with a URI under the control of the attacker. The attacker
then tricks the victim into following the manipulated link to authorize access to the
legitimate client.
攻击者如何欺骗/将受害者重定向到受操纵的链接?这有多容易?有人可以给我一个这种攻击的例子吗?