Server-side redirect by attacker (calc) via new tab

These don't seem particularly interesting in terms of origin spoof, but used to note that opening malicious links in these ways could be used by attackers if they don't have other options.

If using noopener, URL in address bar is about:blank. Otherwise, first redirect URL is shown in address bar.





Open new tab (rel=noopener, target=test3)

Open new tab (target=test4)