3 ms·
The thing with this vulnerability is that it is just an XSS. It has nothing to do with Google apart from the fact they don't run GoogleBot using a recent versi
by geophertz 7y ago
The thing with this vulnerability is that it is just an XSS.
It has nothing to do with Google apart from the fact they don't run GoogleBot using a recent version of Chrome.
The other thing is that if I understand correctly, this could work without JavaScript. You could just inject HTML <a> tags to inject links in XSS
vulnerable website.
PS: Apparently Google Bot has been updated to the latest version of Chromium which means it is even less a vulnerability on Google's side.
- quanticle 7y agoExactly. The breathlessness of the article made no sense to me. It's like someone writing, "Did you know that if someone breaks into your home, they can rearrange the books on your bookshelf‽" Well, yes, of course they can but if someone has broken into my house, unauthorized alphabetization is the least of my worries. Similarly, if there's an XSS vulnerability on my site, Google search index manipulation is pretty far down on the list of things I'm going to be worried about.
- Dylan16807 7y agoThink of it more like a DDOS. If they break into your house, you have bigger worries. If they break into the houses of a hundred thousand strangers, and use them to demonstrate that their site should get all the search results and your site goes on page 5, what can you do?
- skrebbel 7y agoMy compliments on "unauthorized alphabetization". (and the interrobang, obviously)
- michaelt 7y agoIt has nothing to do with Google Some people might expect Google to detect and block black hat SEO techniques? And see this behaviour as Google erroneously miscounting links to pages?
- luckylion 7y agoThe links won't really matter though, because they don't have value. You need somebody to link to the XSS'd URL for the links to help you with SEO, preferably linking to it from the legit page - which will generally not happen, and if you can make it happen, you don't need this attack, you can just link to your page directly.