Bobytiranda
Multimedia Shared

 
 


News

January 16, 2012

URL redirection Vulnerability in Google & Facebook

Url
An open redirect is a vulnerability that exists when a script allows redirectionto an external site by directly calling a specific URL in an unfiltered,unmanaged fashion, which could be used to redirect victims to unintended,malicious web sites. A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect.
A similar vulnerability is reported in Google by “Ucha Gobejishvili ( longrifle0x )“. This problem may assist an attacker to conduct phishing attacks, trojan distribution, spammers.
Url: https://accounts.google.com/o/oauth2/auth?redirect_uri=http://www.something.com
Same vulnerability in Facebook, Discovered by ZeRtOx from Devitel group:

http://www.facebook.com/l.php?h=5AQH8ROsPAQEOTSTw7sgoW1LhviRUBr6iFCcj4C8YmUcC8A&u=www.something.com
Impact of Vulnerability  :
  • The user may be redirected to an untrusted page that contains malware which may then compromise the user’s machine. This will expose the user to extensive risk and the user’s interaction with the web server may also be compromised if the malware conducts keylogging or other attacks that steal credentials, personally identifiable information (PII), or other important data.
  • The user may be subjected to phishing attacks by being redirected to an untrusted page. The phishing attack may point to an attacker controlled web page that appears to be a trusted web site. The phishers may then steal the user’s credentials and then use these credentials to access the legitimate web site.






 
 

 
Logo-Nokia

Nokia flogs 350 vital mobile phone patents

Patent licensing outfit Sisvel has acquired 450 patents from Nokia, 350 of which are essential for mobile telephony, but despite appearances this is no desperate attempt to borrow cash from the future. The patents include 350 w...
by Admin
0

 
 
zapposhack

Zappos coughs to HUGE data breach

Online shoe and apparel outlet Zappos.com has apologised over a massive data breach that exposed the personal details of millions. Up to 24 million customers of the Amazon subsidiary may have been affected by the breach, which ...
by Admin
0

 
 
google

Google MORTIFIED by Mocality’s ‘scalped data’ claims

Google issued an apology to Mocality late on Friday after the startup’s CEO uncovered evidence that employees working for Mountain View had lied about their biz relationship with the Kenyan biz. “We were mortified t...
by Admin
0

 

 
virgin-media-broadband-1-million-0

Virgin Media takes itself in hand after punter-package tickle whoopsie

Updated An email that arrived in the inboxes of an unspecified number of Virgin Media customers on Friday that promised “faster broadband, for less” was embarrassingly pulled by the telco just hours later. The compa...
by Admin
0

 
 
angrybrides

Angry Brides lob stilettos in dowry shakedown takedown

ndian matchmaking service Shaadi.com has launched a new game based on the immensely popular Angry Birdsthat aims to highlight the unfair and illegal practice of demanding dowries in South Asian countries. Angry Brides is hosted...
by Admin
0

 




0 Comments


Be the first to comment!


Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>