4 ms·
Perhaps the ad was using one of the Google redirect tricks? There’s a few google.com endpoints (if I recall) that you can abuse to redirect to arbitrary URLs.
by anonred 8y ago
Perhaps the ad was using one of the Google redirect tricks? There’s a few google.com endpoints (if I recall) that you can abuse to redirect to arbitrary URLs.
- Sephr 8y agoAt first I suspected this as well, but apparently it was a link to itracking[.]services and Bing pre-resolved the redirect chain. You can spoof any domain you want in Bing Ads without needing an open redirect.
- edoceo 8y ago> You can spoof any domain you want in Bing Ads without needing an open redirect. Is that a bug or a feature? It seems like the kind of thing that could erode user trust
- ocdtrekkie 8y agoIt's a feature, Google allows the same. Basically advertisers want to set the links to be tracking links and stuff which may be through third parties which then redirect to their site. So both ad services allow the advertiser to display one URL while directing users to another.
- adanto6840 8y agoSurely they're doing some verification to ensure that either the redirect lands on the advertised TLD, or alternatively that you're at least "in control" of the TLD you're advertising as (similar to GAnalytics verification -- via meta tag, DNS txt entry, etc)?
- utopcell 8y agoGoogle does.
- ocdtrekkie 8y agoDoesn't seem to work much better than whatever solution Bing uses, see https://news.ycombinator.com/item?id=18317051 https://news.ycombinator.com/item?id=18317051 Though that was 2017, and Google might've improved their protections since then.