4 ms·
I think if google (verified with ssl cert etc) is asking for my password, there was a certain expectation there, but you're right, I should be less trusting ;)
by eadz 10y ago
I think if google (verified with ssl cert etc) is asking for my password, there was a certain expectation there, but you're right, I should be less trusting ;)
Here is the demonstration url from the report
https://accounts.google.com/ServiceLogin?service=mail&continue=https://www.google.com/amp/yahoo.com#identifier https://accounts.google.com/ServiceLogin?service=mail&contin...
My point isn't about 'open redirects' not being a security issue, it's that the report should be valid because it's a whitelist bypass.
continue=yahoo.com is blocked
but continue=https://www.google.com/amp/yahoo.com https://www.google.com/amp/yahoo.com is not blocked.
both do the same thing as far as the end user is concerned.
- gyey 10y agocontinue=https://www.google.com/amp/yahoo.com https://www.google.com/amp/yahoo.com is taking me to a Google error page that says yahoo.com is invalid amp code.
- lsaferite 10y agoWeird, it worked perfectly for me just now.
- adrianratnapala 10y agoI am being redirected to a page that will let me change my google account recovery options. My guess is that posting this thing on HN has caused them to fix it. OR maybe I'm being phished.
- gyey 10y agothe /amp/ hack only works for desktop and not mobile. I was on mobile and that's why I got the Google error page.