7 ms·
Furthermore, I can see browsers detecting this type of behavior and prompting the user about it. If a browser sees an encoded URL in the query string, and then
by chacha102 17y ago
Furthermore, I can see browsers detecting this type of behavior and prompting the user about it.
If a browser sees an encoded URL in the query string, and then gets a location header to go to that URL, and that URL is not on the same domain, it would prompt the user that you are leaving that domain.
I can't see many sites that are legitimate, and use redirection techniques that meet all of my criteria.
- IgorPartola 17y agohttp://voice.google.com/ http://voice.google.com/ redirects to http://google.com/voice http://google.com/voice. Technically different domains, but I would be really annoyed if I had to confirm this every time. I suppose you could add a white list, but now we are just annoying people when they first start using a particular install of a browser.
- chacha102 17y agoNo, I'm talking about seeing something like: http://voice.google.com/?r=google.com/voice http://voice.google.com/?r=google.com/voice, where the resulting URL is inside the query_string
- IgorPartola 17y agoSo then we start obfuscating the URL parameters? Or what if google.com/voice is just one step in a series of redirects? What if some "clever" dude decides to protect against this and say base64 encode the r argument to "protect" his app?