4 ms·
I disagree. The linked google page ( https://sites.google.com/site/bughunteruniversity/nonvuln/open-redirect https://sites.google.com/site/bughunteruniversity/n
by eadz 10y ago
I disagree. The linked google page ( https://sites.google.com/site/bughunteruniversity/nonvuln/open-redirect https://sites.google.com/site/bughunteruniversity/nonvuln/op... ) makes the argument about the mouse hover tooltip, as if that is the only risk of an open redirect.
This is much worse, this is a redirect after login. You just logged into google, you entered your 2FA code, and then the next site you arrive at you damn well expect to be google.
Additionally, the OP is correct in that there is a whitelist bypass happening here. Why bother to whitelist *.google.com/ if you can bypass it with a redirect.
- cbsmith 10y ago> then the next site you arrive at you damn well expect to be google. Actually, if it is an untrusted URL, I'm not sure why I'd expect that.
- eadz 10y agoI think if google (verified with ssl cert etc) is asking for my password, there was a certain expectation there, but you're right, I should be less trusting ;) Here is the demonstration url from the report https://accounts.google.com/ServiceLogin?service=mail&continue=https://www.google.com/amp/yahoo.com#identifier https://accounts.google.com/ServiceLogin?service=mail&contin... My point isn't about 'open redirects' not being a security issue, it's that the report should be valid because it's a whitelist bypass. continue=yahoo.com is blocked but continue=https://www.google.com/amp/yahoo.com https://www.google.com/amp/yahoo.com is not blocked. both do the same thing as far as the end user is concerned.
- gyey 10y agocontinue=https://www.google.com/amp/yahoo.com https://www.google.com/amp/yahoo.com is taking me to a Google error page that says yahoo.com is invalid amp code.
- lsaferite 10y agoWeird, it worked perfectly for me just now.
- adrianratnapala 10y agoI am being redirected to a page that will let me change my google account recovery options. My guess is that posting this thing on HN has caused them to fix it. OR maybe I'm being phished.
- gyey 10y agothe /amp/ hack only works for desktop and not mobile. I was on mobile and that's why I got the Google error page.
- admax88q 10y ago> at you damn well expect to be google. That's not really true though. Google serves as an identity provider providing login into 3rd party websites. Plus there's also OAuth prompts when 3rd party services want to use your Google data.
- deleted 10y ago[deleted]
- rathish_g 10y ago> at you damn well expect to be google. If it's again asking for a password, it must be Google.
- djsumdog 10y agoNo, that's not true. Think of every time you click on a "sign in with Google" link. If you're not signed in, it will take you to this login page. The redirect will only send back a token, and only for that site.