Web Hack List

Collected research

Google plugs phishing hole

SecuriTeam Blogs » Exploiting Google for Phishing

Gadi Evron relays Eric Farraro's finding that Google Public Service Search let a site supply its own header and footer markup for the results page, with that markup hosted on Google's own server, so attacker code ran from google.com. Google answered the service with a 403. Evron adds that Google's open redirectors, long used for phishing, remain unfixed.

Record

Document
SecuriTeam Blogs » Exploiting Google for Phishing
Researcher
Gadi Evron
Published by
blogs.securiteam.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Gadi Evron, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .