TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Open redirect on Google.com

5 点作者 nwcs大约 9 年前

1 comment

deckar01大约 9 年前
I discovered a vulnerability in Google Drive last year that allows bypassing the content filter on uploaded files and Google refuses to acknowledge the threat, because my proof of concept demonstrated an open redirect. It bypasses the full content scan, which I later determined also allows me to serve fake Google pages from a Google domain.<p>The bug allowed a malicious actor to share the file, which generated an email from Google containing a link to Google that redirected to payload containing a Gmail worm.<p>I spent an entire weekend reverse engineering the attack and had to wait a month for Google to respond saying they wouldn&#x27;t fix it, because I mentioned open redirect.<p>PoC: <a href="https:&#x2F;&#x2F;googledrive.com&#x2F;host&#x2F;0B8F0jrIiu66GbmFFaGpHOTJ5TUU" rel="nofollow">https:&#x2F;&#x2F;googledrive.com&#x2F;host&#x2F;0B8F0jrIiu66GbmFFaGpHOTJ5TUU</a>