TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Google as open forwarder

1 pointsby daefover 8 years ago
I just received a message via skype, no hi or anything - just to the guts - a link to google<p>https:&#x2F;&#x2F;www.google.com&#x2F;url?sa=t&amp;url=%68%74%74%70%3A%2F%2F%37%37%37%63%6F%6D%2E%72%75&amp;usg=AFQjCNGC3A0xDe0azxmOzcm5L4UlYlbbtQ&amp;stoke#54009<p>from a contact I have not had any contact to from a while, which made me suspicious.<p>Turns out this redirects to some .ru domain (you know how to urldecode)<p>Don&#x27;t get me wrong, from another contact I would have clicked this link w&#x2F;o the blink of an eye.<p>So it seems some skype?spambot?worm?whatever is using google as open redirector.<p>I thought OWASP said those aint cool https:&#x2F;&#x2F;www.owasp.org&#x2F;index.php&#x2F;Top_10_2010-A10-Unvalidated_Redirects_and_Forwards but obv google didn&#x27;t listen...<p>tl;dr<p>Don&#x27;t click google links unless you _trust_ them.

no comments

no comments