4 ms·
It is not. There is no sense at all: you could use manually crafted HTML page with malicious links, there is no benefit in using Google Docs export for this.
by negus 3y ago
It is not. There is no sense at all: you could use manually crafted HTML page with malicious links, there is no benefit in using Google Docs export for this.
- judge2020 3y agoThe benefit is as OP said: it bypasses corporate firewalls because it's a google doc. Although I can only reproduce this redirect page in a published doc page[0], not in a pdf export (unless there's another way to download pdf via url trickery) 0: https://docs.google.com/document/d/e/2PACX-1vR4O-8LwvUPNOcwH55jmSWk32fQqV4z2u-3GvFzcaZO-HYY5PlEfMp_tHWdl9y-HKaunyxKUI3nZAe-/pub https://docs.google.com/document/d/e/2PACX-1vR4O-8LwvUPNOcwH...
- crtasm 3y agoA HTML file exported from google docs is not a google doc and I don't see how or why a firewall would see it as one? The URL to download the export can't be shared as far as I can tell. edit: you can reuse the URL to download the export. tested on another network. it expires fairly quickly though, within a couple minutes it seems.
- darkwater 3y ago> edit: you can reuse the URL to download the export. tested on another network. it expires fairly quickly though, within a couple minutes it seems. (thanks for the test) So it's clearly not a possible real vector, and actually they thought about it being a possible vector, otherwise they would not have put the expiration.
- afandian 3y agoI could reproduce on HTML ZIP export but not PDF.