4 ms·
Here are the steps to reproduce the attack from what I gather: 1. Find a vulnerable site. The author picked Revolut, a 3-year old, well-funded fintech startup.
by apo 7y ago
Here are the steps to reproduce the attack from what I gather:
1. Find a vulnerable site. The author picked Revolut, a 3-year old, well-funded fintech startup. Others might be found at https://www.openbugbounty.org https://www.openbugbounty.org.
2. Inject the script. The author did so by tacking a URL parameter containing script content to a link he obtained from the Revolut site.
3. Preview the attack with Google's Web Rendering Service, which apparently uses the same version of Chrome used by Googlebot.
4. Submit the link to Googlebot for crawling.
5. View the cached page from the Google results page.
> I reported this to Google in November 2018, but after 5 months they had made no headway on the issue (citing internal communication difficulties), and therefore I’m publishing details such that site owners and companies can defend their own sites from this sort of attack. Google have now told me they do not have immediate plans to remedy this.
Translation: Google declares open season on this attack.
- ryanlol 7y ago>Google declares open season on this attack. This has always been the case, people have been exploiting this for at least a decade.
- picklemorty 7y agoWas the first I was thinking